Search CVE reports
2341 – 2350 of 37984 results
Not in release
Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a...
1 affected package
shaarli
| Package | 22.04 LTS |
|---|---|
| shaarli | Not in release |
AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists...
1 affected package
assertj-core
| Package | 22.04 LTS |
|---|---|
| assertj-core | Needs evaluation |
Not in release
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to...
1 affected package
rust-gix-date
| Package | 22.04 LTS |
|---|---|
| rust-gix-date | Not in release |
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a...
1 affected package
gnutls28
| Package | 22.04 LTS |
|---|---|
| gnutls28 | Fixed |
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and...
1 affected package
network-manager
| Package | 22.04 LTS |
|---|---|
| network-manager | Vulnerable |
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a...
1 affected package
gi-docgen
| Package | 22.04 LTS |
|---|---|
| gi-docgen | Needs evaluation |
Not in release
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive...
1 affected package
golang-github-go-viper-mapstructure
| Package | 22.04 LTS |
|---|---|
| golang-github-go-viper-mapstructure | Not in release |
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and...
1 affected package
eslint
| Package | 22.04 LTS |
|---|---|
| eslint | Needs evaluation |
A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_rr_head/_dns_decode_SVCB_HTTPS of the file src/dns.c of the component SVBC Record Parser. The manipulation...
1 affected package
smartdns
| Package | 22.04 LTS |
|---|---|
| smartdns | Needs evaluation |
A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to...
1 affected package
gpac
| Package | 22.04 LTS |
|---|---|
| gpac | Needs evaluation |