Search CVE reports
141 – 150 of 31984 results
editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case ‘[’ when the input pattern contains...
1 affected package
editorconfig-core
Package | 18.04 LTS |
---|---|
editorconfig-core | Vulnerable |
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent...
1 affected package
grpc
Package | 18.04 LTS |
---|---|
grpc | Needs evaluation |
The implementation of atob in “Zabbix JS” allows to create a string with arbitrary content and use it to access internal properties of objects.
1 affected package
zabbix
Package | 18.04 LTS |
---|---|
zabbix | Needs evaluation |
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a...
1 affected package
zabbix
Package | 18.04 LTS |
---|---|
zabbix | Needs evaluation |
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.
1 affected package
spip
Package | 18.04 LTS |
---|---|
spip | Needs evaluation |
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
1 affected package
spip
Package | 18.04 LTS |
---|---|
spip | Needs evaluation |
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be inserted into the log. Instead of the...
1 affected package
tuned
Package | 18.04 LTS |
---|---|
tuned | Needs evaluation |
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute...
1 affected package
tuned
Package | 18.04 LTS |
---|---|
tuned | Needs evaluation |
A flaw was found in the Spring Framework. Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. This flaw allows an attacker to craft...
1 affected package
libspring-java
Package | 18.04 LTS |
---|---|
libspring-java | Needs evaluation |