Search CVE reports
81 – 90 of 429 results
CVE-2021-20291
Medium priorityA deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this...
1 affected packages
golang-github-containers-storage
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-containers-storage | Needs evaluation | Needs evaluation | Needs evaluation | Not in release | Not in release |
CVE-2021-29939
Medium priorityAn issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data.
1 affected packages
rust-stackvector
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rust-stackvector | Needs evaluation | Needs evaluation | Needs evaluation | Not in release | Not in release |
CVE-2021-28090
Medium prioritySome fixes available 4 of 7
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed | Fixed |
CVE-2021-28089
Medium prioritySome fixes available 3 of 6
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
1 affected packages
tor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tor | Not affected | Not affected | Fixed | Fixed | Fixed |
CVE-2019-25025
Medium priorityThe activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is...
1 affected packages
ruby-activerecord-session-store
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-activerecord-session-store | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-3325
Medium priorityMonitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without...
1 affected packages
monitorix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
monitorix | — | — | Not affected | Not in release | Not in release |
CVE-2021-26272
Medium prioritySome fixes available 1 of 6
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
1 affected packages
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | Not affected | Not affected | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2021-26271
Medium prioritySome fixes available 1 of 6
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
1 affected packages
ckeditor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ckeditor | Not affected | Not affected | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2020-28086
Low prioritypass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an...
1 affected packages
password-store
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
password-store | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2017-18926
Medium prioritySome fixes available 12 of 13
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen...
2 affected packages
raptor, raptor2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
raptor | Not in release | Not in release | Not in release | Not in release | Vulnerable |
raptor2 | Fixed | Fixed | Fixed | Fixed | Fixed |