Search CVE reports
301 – 310 of 465 results
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter...
1 affected package
indicator-datetime
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
indicator-datetime | — | — | — | — |
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ipe | — | — | — | — |
libextractor | — | — | — | — |
poppler | — | — | — | — |
xpdf | — | — | — | — |
Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | — | — | — | — |
Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | — | — | — | — |
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption),...
40 affected packages
gdcm, apache2, apr-util, audacity, ayttm...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
gdcm | — | — | — | — |
apache2 | — | — | — | — |
apr-util | — | — | — | — |
audacity | — | — | — | — |
ayttm | — | — | — | — |
cableswig | — | — | — | — |
cadaver | — | — | — | — |
celementtree | — | — | — | — |
cmake | — | — | — | — |
coin3 | — | — | — | — |
expat | — | — | — | — |
ghostscript | — | — | — | — |
grmonitor | — | — | — | — |
insighttoolkit | — | — | — | — |
kompozer | — | — | — | — |
libparagui1.1 | — | — | — | — |
matanza | — | — | — | — |
paraview | — | — | — | — |
poco | — | — | — | — |
python-xml | — | — | — | — |
python2.4 | — | — | — | — |
python2.5 | — | — | — | — |
python2.6 | — | — | — | — |
simgear | — | — | — | — |
sitecopy | — | — | — | — |
smart | — | — | — | — |
swish-e | — | — | — | — |
tdom | — | — | — | — |
texlive-bin | — | — | — | — |
tla | — | — | — | — |
vnc4 | — | — | — | — |
vtk | — | — | — | — |
w3c-libwww | — | — | — | — |
wbxml2 | — | — | — | — |
wxwidgets2.6 | — | — | — | — |
wxwidgets2.8 | — | — | — | — |
wxwindows2.4 | — | — | — | — |
xmlrpc-c | — | — | — | — |
xotcl | — | — | — | — |
xulrunner | — | — | — | — |
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and...
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | — | — | — | — |
Some fixes available 1 of 5
The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the...
1 affected package
torque
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
torque | — | — | — | — |
pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access by unprivileged ports, which allows remote authenticated users to...
1 affected package
torque
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
torque | — | — | — | — |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
40 affected packages
tdom, apache2, apr-util, audacity, ayttm...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tdom | — | — | — | — |
apache2 | — | — | — | — |
apr-util | — | — | — | — |
audacity | — | — | — | — |
ayttm | — | — | — | — |
cableswig | — | — | — | — |
cadaver | — | — | — | — |
celementtree | — | — | — | — |
cmake | — | — | — | — |
coin3 | — | — | — | — |
expat | — | — | — | — |
gdcm | — | — | — | — |
ghostscript | — | — | — | — |
grmonitor | — | — | — | — |
insighttoolkit | — | — | — | — |
kompozer | — | — | — | — |
libparagui1.1 | — | — | — | — |
matanza | — | — | — | — |
paraview | — | — | — | — |
poco | — | — | — | — |
python-xml | — | — | — | — |
python2.4 | — | — | — | — |
python2.5 | — | — | — | — |
python2.6 | — | — | — | — |
simgear | — | — | — | — |
sitecopy | — | — | — | — |
smart | — | — | — | — |
swish-e | — | — | — | — |
texlive-bin | — | — | — | — |
tla | — | — | — | — |
vnc4 | — | — | — | — |
vtk | — | — | — | — |
w3c-libwww | — | — | — | — |
wbxml2 | — | — | — | — |
wxwidgets2.6 | — | — | — | — |
wxwidgets2.8 | — | — | — | — |
wxwindows2.4 | — | — | — | — |
xmlrpc-c | — | — | — | — |
xotcl | — | — | — | — |
xulrunner | — | — | — | — |
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by...
1 affected package
language-selector
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
language-selector | — | — | — | — |