Search CVE reports


Toggle filters

11 – 20 of 1750 results


CVE-2023-3431

Medium priority
Ignored

Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.

1 affected package

plantuml

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
plantuml Ignored Ignored Not affected Not affected
Show less packages

CVE-2017-1000

Medium priority

Some fixes available 8 of 10

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

72 affected packages

linux, linux-azure, linux-azure-edge, linux-euclid, linux-flo...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux Not affected Not affected Not affected Not affected
linux-azure Not affected Not affected Not affected Not affected
linux-azure-edge Not in release Not in release Not in release Not affected
linux-euclid Not in release
linux-flo Not in release
linux-gcp Not affected Not affected Not affected Not affected
linux-gke Not affected Not affected Ignored Not in release
linux-goldfish Not in release
linux-grouper Not in release
linux-hwe Not in release Not in release Not in release Not affected
linux-hwe-edge Not in release Not in release Not in release Not affected
linux-kvm Not in release Not affected Not affected Not affected
linux-lts-trusty Not in release
linux-lts-utopic Not in release
linux-lts-vivid Not in release
linux-lts-wily Not in release
linux-lts-xenial Not in release Not in release Not in release Not in release
linux-maguro Not in release
linux-mako Not in release
linux-manta Not in release
linux-raspi2 Not in release Not in release Ignored Not affected
linux-snapdragon Not in release Not in release Not in release Not affected
linux-oem Not in release Not in release Not in release Not affected
linux-aws Not affected Not affected Not affected Not affected
linux-hwe-5.4 Not in release Not in release Not in release Not affected
linux-hwe-5.15 Not in release Not in release Not affected Not in release
linux-hwe-6.8 Not in release Not affected Not in release Not in release
linux-aws-5.4 Not in release Not in release Not in release Not affected
linux-aws-5.15 Not in release Not in release Not affected Not in release
linux-aws-hwe Not in release Not in release Not in release Not in release
linux-azure-4.15 Not in release Not in release Not in release Not affected
linux-azure-5.4 Not in release Not in release Not in release Not affected
linux-azure-5.15 Not in release Not in release Not affected Not in release
linux-azure-fde Not in release Not affected Ignored Not in release
linux-azure-fde-5.15 Not in release Not in release Not affected Not in release
linux-bluefield Not in release Not in release Not affected Not in release
linux-fips Not in release Not affected Not affected Not affected
linux-aws-fips Not in release Not affected Not affected Not affected
linux-azure-fips Not in release Not affected Not affected Not affected
linux-gcp-fips Not in release Not affected Not affected Not affected
linux-gcp-4.15 Not in release Not in release Not in release Not affected
linux-gcp-5.4 Not in release Not in release Not in release Not affected
linux-gcp-5.15 Not in release Not in release Not affected Not in release
linux-gkeop Not affected Not affected Not affected Not in release
linux-gkeop-5.15 Not in release Not in release Not affected Not in release
linux-ibm Not affected Not affected Not affected Not in release
linux-ibm-5.4 Not in release Not in release Not in release Not affected
linux-ibm-5.15 Not in release Not in release Not affected Not in release
linux-intel Not affected Not in release Not in release Not in release
linux-intel-iotg Not in release Not affected Not in release Not in release
linux-intel-iotg-5.15 Not in release Not in release Not affected Not in release
linux-iot Not in release Not in release Not affected Not in release
linux-intel-iot-realtime Not in release Not affected Not in release Not in release
linux-lowlatency Not affected Not affected Not in release Not in release
linux-lowlatency-hwe-5.15 Not in release Not in release Not affected Not in release
linux-lowlatency-hwe-6.8 Not in release Not affected Not in release Not in release
linux-nvidia Not affected Not affected Not in release Not in release
linux-nvidia-6.5 Not in release Not affected Not in release Not in release
linux-nvidia-6.8 Not in release Not affected Not in release Not in release
linux-nvidia-lowlatency Not affected Not in release Not in release Not in release
linux-oracle Not affected Not affected Not affected Not affected
linux-oracle-5.4 Not in release Not in release Not in release Not affected
linux-oracle-5.15 Not in release Not in release Not affected Not in release
linux-oem-6.8 Not affected Not in release Not in release Not in release
linux-raspi Not affected Not affected Not affected Not in release
linux-raspi-5.4 Not in release Not in release Not in release Not affected
linux-raspi-realtime Not affected Not in release Not in release Not in release
linux-realtime Not affected Not affected Not in release Not in release
linux-riscv Not affected Ignored Ignored Not in release
linux-riscv-5.15 Not in release Not in release Not affected Not in release
linux-riscv-6.8 Not in release Not affected Not in release Not in release
linux-xilinx-zynqmp Not in release Not affected Not affected Not in release
Show all 72 packages Show less packages

CVE-2022-4515

Medium priority
Fixed

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary...

1 affected package

exuberant-ctags

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exuberant-ctags Fixed Fixed Fixed
Show less packages

CVE-2022-42717

Medium priority
Needs evaluation

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host...

1 affected package

vagrant

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vagrant Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2011-4916

Low priority
Ignored

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

18 affected packages

linux, linux-armadaxp, linux-ec2, linux-flo, linux-fsl-imx51...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux
linux-armadaxp
linux-ec2
linux-flo
linux-fsl-imx51
linux-goldfish
linux-grouper
linux-lts-backport-maverick
linux-lts-backport-natty
linux-lts-backport-oneiric
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-maguro
linux-mako
linux-manta
linux-mvl-dove
linux-ti-omap4
Show all 18 packages Show less packages

CVE-2022-1379

Medium priority
Ignored

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery...

1 affected package

plantuml

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
plantuml Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-29577

Medium priority
Needs evaluation

OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because...

1 affected package

libowasp-antisamy-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libowasp-antisamy-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-28367

Medium priority
Needs evaluation

OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.

1 affected package

libowasp-antisamy-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libowasp-antisamy-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-28366

Medium priority
Needs evaluation

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed...

1 affected package

libowasp-antisamy-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libowasp-antisamy-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2011-4917

Low priority
Ignored

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

18 affected packages

linux, linux-armadaxp, linux-ec2, linux-flo, linux-fsl-imx51...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux
linux-armadaxp
linux-ec2
linux-flo
linux-fsl-imx51
linux-goldfish
linux-grouper
linux-lts-backport-maverick
linux-lts-backport-natty
linux-lts-backport-oneiric
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-maguro
linux-mako
linux-manta
linux-mvl-dove
linux-ti-omap4
Show all 18 packages Show less packages