Search CVE reports
171 – 180 of 44512 results
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...
1 affected package
anki
| Package | 20.04 LTS |
|---|---|
| anki | Needs evaluation |
[Unknown description]
1 affected package
wordpress
| Package | 20.04 LTS |
|---|---|
| wordpress | Needs evaluation |
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...
2 affected packages
markdown, python-markdown
| Package | 20.04 LTS |
|---|---|
| markdown | Needs evaluation |
| python-markdown | Needs evaluation |
[Unknown description]
1 affected package
libvirt
| Package | 20.04 LTS |
|---|---|
| libvirt | Needs evaluation |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 20.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
| pdns | Needs evaluation |
| pdns-recursor | Needs evaluation |
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
1 affected package
apr-util
| Package | 20.04 LTS |
|---|---|
| apr-util | Needs evaluation |
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes...
1 affected package
apr-util
| Package | 20.04 LTS |
|---|---|
| apr-util | Needs evaluation |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
1 affected package
apr-util
| Package | 20.04 LTS |
|---|---|
| apr-util | Needs evaluation |
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses theĀ apr_xml_quote_elem() function. Users are recommended to upgrade to...
1 affected package
apr-util
| Package | 20.04 LTS |
|---|---|
| apr-util | Needs evaluation |
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...
1 affected package
policycoreutils
| Package | 20.04 LTS |
|---|---|
| policycoreutils | Needs evaluation |