Search CVE reports
11 – 17 of 17 results
CVE-2013-6780
Medium priorityCross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
3 affected packages
maas, yui, yui3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | — | Not affected |
yui | — | — | — | — | Not affected |
yui3 | — | — | — | — | Not affected |
CVE-2013-1057
Medium priorityUntrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
1 affected packages
maas
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | — | — |
CVE-2013-1058
Medium prioritymaas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
1 affected packages
maas
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | — | — |
CVE-2012-5883
Medium priorityCross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows...
2 affected packages
maas, yui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | Not affected | Not affected |
yui | — | — | — | Not in release | Not affected |
CVE-2012-5882
Medium priorityCross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.
2 affected packages
maas, yui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | Not affected | Not affected |
yui | — | — | — | Not in release | Not affected |
CVE-2012-5881
Medium priorityCross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.
2 affected packages
maas, yui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maas | — | — | — | Not affected | Not affected |
yui | — | — | — | Not in release | Not affected |
CVE-2012-2395
Medium priorityIncomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
2 affected packages
cobbler, maas-provision
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cobbler | — | — | — | Not in release | Not affected |
maas-provision | — | — | — | Not in release | Not in release |