Search CVE reports
581 – 590 of 48446 results
Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic...
1 affected package
putty
| Package | 16.04 LTS |
|---|---|
| putty | Needs evaluation |
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity....
1 affected package
pygments
| Package | 16.04 LTS |
|---|---|
| pygments | Needs evaluation |
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
1 affected package
sogo
| Package | 16.04 LTS |
|---|---|
| sogo | Needs evaluation |
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
1 affected package
spip
| Package | 16.04 LTS |
|---|---|
| spip | Needs evaluation |
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
1 affected package
sogo
| Package | 16.04 LTS |
|---|---|
| sogo | Needs evaluation |
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From...
1 affected package
deluge
| Package | 16.04 LTS |
|---|---|
| deluge | Needs evaluation |
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into...
1 affected package
deluge
| Package | 16.04 LTS |
|---|---|
| deluge | Needs evaluation |
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000...
1 affected package
pidgin
| Package | 16.04 LTS |
|---|---|
| pidgin | Needs evaluation |