Search CVE reports
421 – 430 of 36697 results
Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static...
3 affected packages
golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3
| Package | 22.04 LTS |
|---|---|
| golang-github-labstack-echo | Not affected |
| golang-github-labstack-echo.v2 | Not affected |
| golang-github-labstack-echo.v3 | Not affected |
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login....
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in...
1 affected package
openbabel
| Package | 22.04 LTS |
|---|---|
| openbabel | Needs evaluation |
A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler....
1 affected package
openbabel
| Package | 22.04 LTS |
|---|---|
| openbabel | Needs evaluation |
Not in release
[Unknown description]
1 affected package
rust-rpm-sequoia
| Package | 22.04 LTS |
|---|---|
| rust-rpm-sequoia | Not in release |
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full...
1 affected package
orthanc
| Package | 22.04 LTS |
|---|---|
| orthanc | Needs evaluation |
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending...
1 affected package
gsoap
| Package | 22.04 LTS |
|---|---|
| gsoap | Needs evaluation |