Search CVE reports
31 – 40 of 37199 results
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in...
1 affected package
openbabel
| Package | 20.04 LTS |
|---|---|
| openbabel | Needs evaluation |
A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler....
1 affected package
openbabel
| Package | 20.04 LTS |
|---|---|
| openbabel | Needs evaluation |
SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and...
1 affected package
hdf5
| Package | 20.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static...
3 affected packages
golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3
| Package | 20.04 LTS |
|---|---|
| golang-github-labstack-echo | — |
| golang-github-labstack-echo.v2 | Not affected |
| golang-github-labstack-echo.v3 | Not affected |
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
1 affected package
qemu
| Package | 20.04 LTS |
|---|---|
| qemu | Needs evaluation |
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login....
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |