Search CVE reports


Toggle filters

13831 – 13840 of 44107 results

Status is adjusted based on your filters.


CVE-2023-37769

Medium priority
Vulnerable

stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.

1 affected package

pixman

Package 16.04 LTS
pixman Vulnerable
Show less packages

CVE-2023-28864

Medium priority
Needs evaluation

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed...

1 affected package

chef

Package 16.04 LTS
chef Needs evaluation
Show less packages

CVE-2021-31294

Medium priority
Needs evaluation

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before...

1 affected package

redis

Package 16.04 LTS
redis Needs evaluation
Show less packages

CVE-2023-38350

Medium priority
Ignored

PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.

1 affected package

pnp4nagios

Package 16.04 LTS
pnp4nagios Ignored
Show less packages

CVE-2023-38349

Medium priority
Ignored

PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.

1 affected package

pnp4nagios

Package 16.04 LTS
pnp4nagios Ignored
Show less packages

CVE-2023-38336

Medium priority
Needs evaluation

netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.

1 affected package

netkit-rsh

Package 16.04 LTS
netkit-rsh Needs evaluation
Show less packages

CVE-2023-37464

Medium priority
Ignored

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says...

1 affected package

cjose

Package 16.04 LTS
cjose Ignored
Show less packages

CVE-2023-38325

Medium priority
Not affected

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

1 affected package

python-cryptography

Package 16.04 LTS
python-cryptography Not affected
Show less packages

CVE-2023-38253

Low priority
Needs evaluation

An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

1 affected package

w3m

Package 16.04 LTS
w3m Needs evaluation
Show less packages

CVE-2023-38252

Low priority
Needs evaluation

An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

1 affected package

w3m

Package 16.04 LTS
w3m Needs evaluation
Show less packages