Search CVE reports
1291 – 1300 of 55813 results
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip...
1 affected package
calibre
| Package | 16.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does...
1 affected package
calibre
| Package | 16.04 LTS |
|---|---|
| calibre | Needs evaluation |
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying...
1 affected package
libgit2
| Package | 16.04 LTS |
|---|---|
| libgit2 | Needs evaluation |
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...
1 affected package
mongo-java-driver
| Package | 16.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger...
1 affected package
freeipa
| Package | 16.04 LTS |
|---|---|
| freeipa | Needs evaluation |
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 16.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | — |
| freerdp3 | — |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 16.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | — |
| freerdp3 | — |