Search CVE reports
14811 – 14820 of 44652 results
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
1 affected package
nagvis
Package | 16.04 LTS |
---|---|
nagvis | Needs evaluation |
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting...
1 affected package
matrix-synapse
Package | 16.04 LTS |
---|---|
matrix-synapse | Ignored |
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that...
1 affected package
matrix-synapse
Package | 16.04 LTS |
---|---|
matrix-synapse | Ignored |
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The...
1 affected package
c-ares
Package | 16.04 LTS |
---|---|
c-ares | Fixed |
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so...
1 affected package
c-ares
Package | 16.04 LTS |
---|---|
c-ares | Not affected |
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally...
1 affected package
c-ares
Package | 16.04 LTS |
---|---|
c-ares | Fixed |
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as...
1 affected package
c-ares
Package | 16.04 LTS |
---|---|
c-ares | Not affected |
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the...
3 affected packages
libjpeg9, libjpeg-turbo, libjpeg6b
Package | 16.04 LTS |
---|---|
libjpeg9 | Not affected |
libjpeg-turbo | Not affected |
libjpeg6b | Not affected |
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice...
1 affected package
libreoffice
Package | 16.04 LTS |
---|---|
libreoffice | Ignored |
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the...
1 affected package
libreoffice
Package | 16.04 LTS |
---|---|
libreoffice | Ignored |