Search CVE reports
371 – 380 of 36093 results
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three...
1 affected package
rails
| Package | 22.04 LTS |
|---|---|
| rails | Needs evaluation |
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular...
1 affected package
mediawiki
| Package | 22.04 LTS |
|---|---|
| mediawiki | Needs evaluation |
SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
1 affected package
python-geopandas
| Package | 22.04 LTS |
|---|---|
| python-geopandas | Needs evaluation |
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and...
1 affected package
salt
| Package | 22.04 LTS |
|---|---|
| salt | Needs evaluation |
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.
1 affected package
salt
| Package | 22.04 LTS |
|---|---|
| salt | Needs evaluation |
Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service
1 affected package
openvpn
| Package | 22.04 LTS |
|---|---|
| openvpn | Not affected |
Not in release
Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in...
1 affected package
tryton-sao
| Package | 22.04 LTS |
|---|---|
| tryton-sao | Not in release |
Not in release
Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and...
1 affected package
dolibarr
| Package | 22.04 LTS |
|---|---|
| dolibarr | Not in release |
Not in release
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.3.6 through 5.3.3, a RangeError vulnerability exists in the numeric...
1 affected package
node-webfont
| Package | 22.04 LTS |
|---|---|
| node-webfont | Not in release |
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |