Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

101 – 110 of 429 results


CVE-2020-9440

Medium priority
Ignored

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

1 affected packages

ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ckeditor Ignored Ignored Ignored Ignored
Show less packages

CVE-2020-9281

Medium priority

Some fixes available 3 of 6

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

1 affected packages

ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ckeditor Not affected Fixed Fixed Fixed
Show less packages

CVE-2020-8516

Medium priority
Ignored

** DISPUTED ** The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit...

1 affected packages

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tor Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-2929

Medium priority

Some fixes available 2 of 4

The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed...

1 affected packages

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tor Not affected
Show less packages

CVE-2015-2928

Medium priority

Some fixes available 2 of 4

The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.

1 affected packages

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tor Not affected
Show less packages

CVE-2015-2689

Low priority

Some fixes available 2 of 4

Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon...

1 affected packages

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tor Not affected
Show less packages

CVE-2015-2688

Low priority

Some fixes available 2 of 4

buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and...

1 affected packages

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tor Not affected
Show less packages

CVE-2014-9720

Low priority
Ignored

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of...

1 affected packages

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
python-tornado Not affected Not affected
Show less packages

CVE-2020-7040

Medium priority

Some fixes available 3 of 5

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock...

1 affected packages

storebackup

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
storebackup Fixed Fixed Fixed
Show less packages

CVE-2010-4654

Medium priority
Needs evaluation

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

5 affected packages

ipe, koffice, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Needs evaluation
Show less packages