Search CVE reports
21 – 30 of 54269 results
The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace...
2 affected packages
docker.io, docker.io-app
| Package | 22.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to...
1 affected package
jackrabbit
| Package | 22.04 LTS |
|---|---|
| jackrabbit | Needs evaluation |
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match...
1 affected package
jackrabbit
| Package | 22.04 LTS |
|---|---|
| jackrabbit | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 22.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 22.04 LTS |
|---|---|
| openvpn | Needs evaluation |
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
2 affected packages
golang-golang-x-text, golang-x-text
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-text | Needs evaluation |
| golang-x-text | Not in release |
A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a...
1 affected package
visidata
| Package | 22.04 LTS |
|---|---|
| visidata | Needs evaluation |
A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a...
1 affected package
visidata
| Package | 22.04 LTS |
|---|---|
| visidata | Needs evaluation |
A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file...
1 affected package
flatpak-builder
| Package | 22.04 LTS |
|---|---|
| flatpak-builder | Needs evaluation |
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may...
1 affected package
zaqar
| Package | 22.04 LTS |
|---|---|
| zaqar | Needs evaluation |