Search CVE reports
111 – 120 of 465 results
Some fixes available 2 of 11
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
2 affected packages
raptor, raptor2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
raptor | Not in release | Not in release | Not in release | Not in release |
raptor2 | Not affected | Fixed | Fixed | Needs evaluation |
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm,...
2 affected packages
ckeditor, ckeditor3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ckeditor | Not affected | Not affected | Not affected | Not affected |
ckeditor3 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this...
1 affected package
golang-github-containers-storage
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-github-containers-storage | Not affected | Not affected | Vulnerable | Not in release |
An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data.
1 affected package
rust-stackvector
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rust-stackvector | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
Some fixes available 4 of 7
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed |
Some fixes available 3 of 6
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed |
The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is...
1 affected package
ruby-activerecord-session-store
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ruby-activerecord-session-store | Not in release | Not in release | Not in release | Needs evaluation |
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without...
1 affected package
monitorix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
monitorix | — | — | Not affected | Not in release |
Some fixes available 1 of 6
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
1 affected package
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ckeditor | Not affected | Not affected | Needs evaluation | Needs evaluation |
Some fixes available 1 of 6
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
1 affected package
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ckeditor | Not affected | Not affected | Needs evaluation | Needs evaluation |