Search CVE reports
891 – 900 of 41184 results
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious...
2 affected packages
request-tracker4, request-tracker5
| Package | 20.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | — |
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is...
2 affected packages
request-tracker4, request-tracker5
| Package | 20.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | — |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes...
1 affected package
libheif
| Package | 20.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...
1 affected package
libheif
| Package | 20.04 LTS |
|---|---|
| libheif | Needs evaluation |
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...
1 affected package
ruby-devise
| Package | 20.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.
2 affected packages
golang-golang-x-sys, google-guest-agent
| Package | 20.04 LTS |
|---|---|
| golang-golang-x-sys | Needs evaluation |
| google-guest-agent | Needs evaluation |
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...
1 affected package
pcmanfm-qt
| Package | 20.04 LTS |
|---|---|
| pcmanfm-qt | Needs evaluation |
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...
7 affected packages
jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...
| Package | 20.04 LTS |
|---|---|
| jruby | Needs evaluation |
| ruby2.3 | — |
| ruby2.5 | — |
| ruby2.7 | Needs evaluation |
| ruby3.0 | — |
| ruby3.2 | — |
| ruby3.3 | — |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 20.04 LTS |
|---|---|
| golang-golang-x-net-dev | Needs evaluation |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 20.04 LTS |
|---|---|
| golang-golang-x-net-dev | Needs evaluation |