Search CVE reports
17901 – 17910 of 44699 results
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
1 affected package
wkhtmltopdf
Package | 16.04 LTS |
---|---|
wkhtmltopdf | Fixed |
Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as...
1 affected package
minetest
Package | 16.04 LTS |
---|---|
minetest | Needs evaluation |
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
1 affected package
w3m
Package | 16.04 LTS |
---|---|
w3m | Vulnerable |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
1 affected package
vim
Package | 16.04 LTS |
---|---|
vim | Not affected |
Not in release
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type`...
1 affected package
node-undici
Package | 16.04 LTS |
---|---|
node-undici | Not in release |
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
1 affected package
schroot
Package | 16.04 LTS |
---|---|
schroot | Fixed |
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in...
7 affected packages
postgresql-10, postgresql-12, postgresql-13, postgresql-14, postgresql-9.1...
Package | 16.04 LTS |
---|---|
postgresql-10 | Not in release |
postgresql-12 | Not in release |
postgresql-13 | Not in release |
postgresql-14 | Not in release |
postgresql-9.1 | Not in release |
postgresql-9.3 | Not in release |
postgresql-9.5 | Ignored |
Not in release
undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`. If a user...
1 affected package
node-undici
Package | 16.04 LTS |
---|---|
node-undici | Not in release |
Not in release
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the...
2 affected packages
golang-code.gitea-git, golang-code.gitea-sdk
Package | 16.04 LTS |
---|---|
golang-code.gitea-git | Not in release |
golang-code.gitea-sdk | Not in release |
Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.
1 affected package
chromium-browser
Package | 16.04 LTS |
---|---|
chromium-browser | Ignored |