Search CVE reports


Toggle filters

91 – 100 of 488 results


CVE-2022-48110

Medium priority
Ignored

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation...

4 affected packages

ldap-account-manager, request-tracker4, ckeditor3, ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Not affected Not affected Not affected Not affected
request-tracker4 Not affected Not affected Not affected Not affected
ckeditor3 Not affected Not affected Not affected Not affected
ckeditor Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-0341

Medium priority
Fixed

A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6...

1 affected package

editorconfig-core

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
editorconfig-core Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-23589

Medium priority
Needs evaluation

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-22457

Medium priority
Needs evaluation

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-45907

Medium priority
Needs evaluation

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release Not in release
Show less packages

CVE-2022-36180

Medium priority
Needs evaluation

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS)...

1 affected package

fusiondirectory

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fusiondirectory Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-36179

Medium priority
Needs evaluation

Fusiondirectory 1.3 suffers from Improper Session Handling.

1 affected package

fusiondirectory

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fusiondirectory Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-39369

Medium priority

Some fixes available 4 of 9

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...

3 affected packages

php-cas, ocsinventory-server, moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-cas Not affected Fixed Fixed Ignored
ocsinventory-server Not affected Fixed Not affected Not affected
moodle Not in release Not in release Not in release Ignored
Show less packages

CVE-2022-31175

Medium priority
Needs evaluation

CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript...

4 affected packages

request-tracker4, ckeditor, ckeditor3, ldap-account-manager

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-33903

Medium priority
Ignored

Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor Not affected Not affected Not affected
Show less packages