Search CVE reports
481 – 490 of 37641 results
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace,...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
1 affected package
osslsigncode
| Package | 22.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper...
2 affected packages
libpf4j-java, libpf4j-update-java
| Package | 22.04 LTS |
|---|---|
| libpf4j-java | Needs evaluation |
| libpf4j-update-java | Needs evaluation |
Not in release
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
1 affected package
plexus-utils
| Package | 22.04 LTS |
|---|---|
| plexus-utils | Not in release |
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
1 affected package
fontconfig
| Package | 22.04 LTS |
|---|---|
| fontconfig | Not affected |
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the...
2 affected packages
requests, python-pip
| Package | 22.04 LTS |
|---|---|
| requests | Needs evaluation |
| python-pip | Needs evaluation |
Not in release
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due...
1 affected package
gitlab
| Package | 22.04 LTS |
|---|---|
| gitlab | Not in release |