Search CVE reports
101 – 110 of 429 results
CVE-2020-9440
Medium priorityA cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
1 affected packages
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | — | Ignored | Ignored | Ignored | Ignored |
CVE-2020-9281
Medium prioritySome fixes available 3 of 6
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
1 affected packages
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | — | Not affected | Fixed | Fixed | Fixed |
CVE-2020-8516
Medium priority** DISPUTED ** The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit...
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2015-2929
Medium prioritySome fixes available 2 of 4
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed...
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | — | — | — | — | Not affected |
CVE-2015-2928
Medium prioritySome fixes available 2 of 4
The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | — | — | — | — | Not affected |
CVE-2015-2689
Low prioritySome fixes available 2 of 4
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon...
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | — | — | — | — | Not affected |
CVE-2015-2688
Low prioritySome fixes available 2 of 4
buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and...
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | — | — | — | — | Not affected |
CVE-2014-9720
Low priorityTornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of...
1 affected packages
python-tornado
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-tornado | — | — | — | Not affected | Not affected |
CVE-2020-7040
Medium prioritySome fixes available 3 of 5
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock...
1 affected packages
storebackup
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
storebackup | — | — | Fixed | Fixed | Fixed |
CVE-2010-4654
Medium prioritypoppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
5 affected packages
ipe, koffice, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
koffice | Not in release | Not in release | Not in release | Not in release | Not in release |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Not affected | Not affected | Not in release | Not affected | Needs evaluation |