Search CVE reports
51 – 60 of 58662 results
web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).
1 affected package
web2py
| Package | 16.04 LTS |
|---|---|
| web2py | Needs evaluation |
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...
1 affected package
libemail-sender-perl
| Package | 16.04 LTS |
|---|---|
| libemail-sender-perl | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was...
1 affected package
mina2
| Package | 16.04 LTS |
|---|---|
| mina2 | Needs evaluation |
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...
1 affected package
fetchmail
| Package | 16.04 LTS |
|---|---|
| fetchmail | Needs evaluation |
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...
1 affected package
dogtag-pki
| Package | 16.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Not affected |
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Not affected |