Search CVE reports
51 – 60 of 37885 results
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9.
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0...
1 affected package
drupal7
Package | 16.04 LTS |
---|---|
drupal7 | Needs evaluation |
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are...
1 affected package
hugo
Package | 16.04 LTS |
---|---|
hugo | Needs evaluation |
ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.
1 affected package
colpack
Package | 16.04 LTS |
---|---|
colpack | Needs evaluation |
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
1 affected package
libposix-2008-perl
Package | 16.04 LTS |
---|---|
libposix-2008-perl | Needs evaluation |
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users...
1 affected package
subversion
Package | 16.04 LTS |
---|---|
subversion | Needs evaluation |