Search CVE reports
101 – 110 of 36612 results
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack...
1 affected package
pluxml
| Package | 22.04 LTS |
|---|---|
| pluxml | Needs evaluation |
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor...
1 affected package
pluxml
| Package | 22.04 LTS |
|---|---|
| pluxml | Needs evaluation |
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the...
1 affected package
pluxml
| Package | 22.04 LTS |
|---|---|
| pluxml | Needs evaluation |
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply...
1 affected package
ruby-foreman
| Package | 22.04 LTS |
|---|---|
| ruby-foreman | Needs evaluation |
Not in release
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1)...
1 affected package
libcrypt-sysrandom-xs-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-sysrandom-xs-perl | Not in release |
A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires...
1 affected package
vips
| Package | 22.04 LTS |
|---|---|
| vips | Needs evaluation |
A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The...
1 affected package
vips
| Package | 22.04 LTS |
|---|---|
| vips | Needs evaluation |
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to...
1 affected package
vips
| Package | 22.04 LTS |
|---|---|
| vips | Needs evaluation |
A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The...
1 affected package
vips
| Package | 22.04 LTS |
|---|---|
| vips | Needs evaluation |
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client...
1 affected package
inetutils
| Package | 22.04 LTS |
|---|---|
| inetutils | Vulnerable |