Search CVE reports


Toggle filters

1711 – 1720 of 1756 results


CVE-2010-4348

Low priority
Not affected

Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the db_type parameter, related to an unsafe call by MantisBT to a...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2010-3448

Low priority

Some fixes available 10 of 13

drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a...

12 affected packages

linux, linux-armadaxp, linux-ec2, linux-fsl-imx51, linux-lts-backport-maverick...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux
linux-armadaxp
linux-ec2
linux-fsl-imx51
linux-lts-backport-maverick
linux-lts-backport-natty
linux-lts-backport-oneiric
linux-lts-quantal
linux-lts-raring
linux-mvl-dove
linux-source-2.6.15
linux-ti-omap4
Show all 12 packages Show less packages

CVE-2010-3763

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2010-3303

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2010-2955

Low priority

Some fixes available 12 of 22

The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error...

26 affected packages

linux-raspi2, linux, linux-armadaxp, linux-backports-modules-2.6.24, linux-backports-modules-2.6.28...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux-raspi2
linux
linux-armadaxp
linux-backports-modules-2.6.24
linux-backports-modules-2.6.28
linux-backports-modules-2.6.32
linux-ec2
linux-flo
linux-fsl-imx51
linux-goldfish
linux-grouper
linux-lts-backport-maverick
linux-lts-backport-natty
linux-lts-backport-oneiric
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-lts-trusty
linux-lts-utopic
linux-lts-vivid
linux-maguro
linux-mako
linux-manta
linux-mvl-dove
linux-source-2.6.15
linux-ti-omap4
Show all 26 packages Show less packages

CVE-2010-2802

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2 allows remote authenticated users to inject arbitrary web script or HTML via an HTML document with a .gif filename extension, related to inline attachments.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2010-2574

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2008-4689

Low priority
Ignored

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2008-4688

Low priority
Ignored

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2008-4687

Low priority
Ignored

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages