Search CVE reports
1101 – 1110 of 55618 results
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 16.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | — |
| freerdp3 | — |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 16.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | — |
| freerdp3 | — |
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and...
1 affected package
djangorestframework
| Package | 16.04 LTS |
|---|---|
| djangorestframework | Needs evaluation |
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI...
1 affected package
flawfinder
| Package | 16.04 LTS |
|---|---|
| flawfinder | Needs evaluation |
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser...
1 affected package
djangorestframework
| Package | 16.04 LTS |
|---|---|
| djangorestframework | Needs evaluation |
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |