Search CVE reports


Toggle filters

17901 – 17910 of 44699 results

Status is adjusted based on your filters.


CVE-2020-21365

Medium priority
Fixed

Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.

1 affected package

wkhtmltopdf

Package 16.04 LTS
wkhtmltopdf Fixed
Show less packages

CVE-2022-35978

Medium priority
Needs evaluation

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as...

1 affected package

minetest

Package 16.04 LTS
minetest Needs evaluation
Show less packages

CVE-2022-38223

Medium priority
Vulnerable

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

1 affected package

w3m

Package 16.04 LTS
w3m Vulnerable
Show less packages

CVE-2022-2819

Medium priority
Not affected

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

1 affected package

vim

Package 16.04 LTS
vim Not affected
Show less packages

CVE-2022-35948

Medium priority

Not in release

undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type`...

1 affected package

node-undici

Package 16.04 LTS
node-undici Not in release
Show less packages

CVE-2022-2787

Medium priority
Fixed

Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

1 affected package

schroot

Package 16.04 LTS
schroot Fixed
Show less packages

CVE-2022-2625

Medium priority
Ignored

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in...

7 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-14, postgresql-9.1...

Package 16.04 LTS
postgresql-10 Not in release
postgresql-12 Not in release
postgresql-13 Not in release
postgresql-14 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Ignored
Show all 7 packages Show less packages

CVE-2022-35949

Medium priority

Not in release

undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`. If a user...

1 affected package

node-undici

Package 16.04 LTS
node-undici Not in release
Show less packages

CVE-2022-38183

Low priority

Not in release

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the...

2 affected packages

golang-code.gitea-git, golang-code.gitea-sdk

Package 16.04 LTS
golang-code.gitea-git Not in release
golang-code.gitea-sdk Not in release
Show less packages

CVE-2022-2624

Medium priority
Ignored

Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.

1 affected package

chromium-browser

Package 16.04 LTS
chromium-browser Ignored
Show less packages