Search CVE reports
71 – 80 of 429 results
CVE-2020-36471
Medium priorityAn issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.
1 affected packages
rust-generator
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rust-generator | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-33900
Low priorityWhile investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any...
1 affected packages
apache-directory-server
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
apache-directory-server | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2021-34550
Medium prioritySome fixes available 2 of 5
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed | Not affected |
CVE-2021-34549
Medium prioritySome fixes available 3 of 6
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed | Fixed |
CVE-2021-34548
Medium prioritySome fixes available 1 of 4
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Not affected | Not affected |
CVE-2021-31997
Medium priorityA UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2...
1 affected packages
postorius
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postorius | — | Not affected | Not affected | Not affected | Ignored |
CVE-2021-33829
Medium prioritySome fixes available 3 of 5
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
1 affected packages
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-3538
Medium priorityA flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs...
1 affected packages
golang-github-satori-go.uuid
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-satori-go.uuid | — | Not affected | Not affected | Not affected | Ignored |
CVE-2020-25713
Low priorityA malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
2 affected packages
raptor, raptor2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
raptor | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
raptor2 | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2021-21391
Medium priorityCKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm,...
2 affected packages
ckeditor, ckeditor3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | Not affected | Not affected | Not affected | Not affected | Not affected |
ckeditor3 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |