Search CVE reports
321 – 330 of 465 results
Some fixes available 3 of 5
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject...
1 affected package
fckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
fckeditor | — | — | — | — |
readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
40 affected packages
expat, apr-util, audacity, ayttm, cableswig...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
expat | — | — | — | Not affected |
apr-util | — | — | — | Ignored |
audacity | — | — | — | Not affected |
ayttm | — | — | — | Not in release |
cableswig | — | — | — | Not in release |
cadaver | — | — | — | Not affected |
coin3 | — | — | — | Not affected |
gdcm | — | — | — | Not affected |
insighttoolkit | — | — | — | Not in release |
matanza | — | — | — | Not affected |
paraview | — | — | — | Not affected |
poco | — | — | — | Not affected |
simgear | — | — | — | Not affected |
sitecopy | — | — | — | Not affected |
swish-e | — | — | — | Not affected |
tdom | — | — | — | Not affected |
texlive-bin | — | — | — | Ignored |
tla | — | — | — | Not affected |
vnc4 | — | — | — | Ignored |
vtk | — | — | — | Not in release |
wbxml2 | — | — | — | Not affected |
wxwidgets2.8 | — | — | — | Not in release |
apache2 | — | — | — | Ignored |
celementtree | — | — | — | Not in release |
cmake | — | — | — | Ignored |
ghostscript | — | — | — | Ignored |
grmonitor | — | — | — | Not in release |
kompozer | — | — | — | Not in release |
libparagui1.1 | — | — | — | Not in release |
python-xml | — | — | — | Not in release |
python2.4 | — | — | — | Not in release |
python2.5 | — | — | — | Not in release |
python2.6 | — | — | — | Not in release |
smart | — | — | — | Ignored |
w3c-libwww | — | — | — | Not in release |
wxwidgets2.6 | — | — | — | Not in release |
wxwindows2.4 | — | — | — | Not in release |
xmlrpc-c | — | — | — | Ignored |
xotcl | — | — | — | Not affected |
xulrunner | — | — | — | Not in release |
Some fixes available 44 of 403
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause...
41 affected packages
ayttm, poco, celementtree, python-xml, paraview...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ayttm | Not in release | Not in release | Not in release | Not in release |
poco | Not affected | Not affected | Not affected | Not affected |
celementtree | Not in release | Not in release | Not in release | Not in release |
python-xml | Not in release | Not in release | Not in release | Not in release |
paraview | Not affected | Not affected | Not affected | Not affected |
kompozer | Not in release | Not in release | Not in release | Not in release |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
swish-e | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
cadaver | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
audacity | Not affected | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
python2.4 | Not in release | Not in release | Not in release | Not in release |
python2.5 | Not in release | Not in release | Not in release | Not in release |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
vnc4 | Not in release | Not in release | Not in release | Ignored |
w3c-libwww | Not in release | Not in release | Not in release | Not in release |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
sitecopy | Not in release | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
xulrunner | Not in release | Not in release | Not in release | Not in release |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
matanza | Ignored | Ignored | Ignored | Ignored |
libxmltok | Fixed | Fixed | Fixed | Fixed |
xotcl | Not affected | Not affected | Not affected | Not affected |
coin3 | Not affected | Not affected | Not affected | Vulnerable |
gdcm | Not affected | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
grmonitor | Not in release | Not in release | Not in release | Not in release |
expat | Not affected | Not affected | Not affected | Not affected |
python2.6 | Not in release | Not in release | Not in release | Not in release |
wxwindows2.4 | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Fixed | Fixed | Fixed | Fixed |
Some fixes available 37 of 392
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption)...
41 affected packages
cmake, paraview, python-xml, libparagui1.1, poco...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cmake | Not affected | Not affected | Not affected | Not affected |
paraview | Not affected | Not affected | Not affected | Not affected |
python-xml | Not in release | Not in release | Not in release | Not in release |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
poco | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
ayttm | Not in release | Not in release | Not in release | Not in release |
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
smart | Not in release | Not in release | Not in release | Not affected |
vnc4 | Not in release | Not in release | Not in release | Ignored |
w3c-libwww | Not in release | Not in release | Not in release | Not in release |
xotcl | Not affected | Not affected | Not affected | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwindows2.4 | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Vulnerable |
gdcm | Not affected | Not affected | Not affected | Not affected |
grmonitor | Not in release | Not in release | Not in release | Not in release |
simgear | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
cadaver | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
swish-e | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
expat | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
celementtree | Not in release | Not in release | Not in release | Not in release |
ghostscript | Not affected | Not affected | Not affected | Not affected |
python2.4 | Not in release | Not in release | Not in release | Not in release |
python2.5 | Not in release | Not in release | Not in release | Not in release |
python2.6 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
libxmltok | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Fixed | Fixed | Fixed | Fixed |
xulrunner | Not in release | Not in release | Not in release | Not in release |
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle...
2 affected packages
ubuntuone-client, ubuntuone-storage-protocol
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ubuntuone-client | — | — | — | — |
ubuntuone-storage-protocol | — | — | — | — |
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
1 affected package
python-tornado
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python-tornado | — | — | — | — |
Some fixes available 6 of 10
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted...
4 affected packages
libreoffice, openoffice.org, raptor, raptor2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libreoffice | — | — | — | — |
openoffice.org | — | — | — | — |
raptor | — | — | — | — |
raptor2 | — | — | — | — |
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
1 affected package
torque
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
torque | — | — | — | — |
Some fixes available 4 of 6
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message,...
2 affected packages
plib, torcs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
plib | — | — | — | — |
torcs | — | — | — | — |
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading...
1 affected package
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tor | — | — | — | — |