Search CVE reports


Toggle filters

241 – 250 of 490 results


CVE-2018-12482

Medium priority
Vulnerable

OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14347

Medium priority

Some fixes available 2 of 5

GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14346

Medium priority

Some fixes available 2 of 5

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1000558

Negligible priority
Needs evaluation

OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-1000557

Negligible priority
Needs evaluation

OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) code within...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-12356

Medium priority
Vulnerable

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers...

1 affected package

password-store

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
password-store Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10539

Medium priority

Some fixes available 16 of 18

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular...

1 affected package

node-negotiator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-negotiator Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-11093

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.

1 affected package

ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected
Show less packages

CVE-2018-11033

Negligible priority
Vulnerable

The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-10361

Medium priority
Vulnerable

An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on...

1 affected package

ktexteditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ktexteditor Not affected Not affected Not affected Vulnerable
Show less packages