Search CVE reports
1301 – 1310 of 56918 results
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via...
1 affected package
mysql-connector-java
| Package | 16.04 LTS |
|---|---|
| mysql-connector-java | Needs evaluation |
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to...
1 affected package
mysql-connector-java
| Package | 16.04 LTS |
|---|---|
| mysql-connector-java | Needs evaluation |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32,...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 16.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | Ignored |
| openjdk-lts | — |
| openjdk-13 | — |
| openjdk-16 | — |
| openjdk-17 | — |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | — |
| openjdk-21-crac | — |
| openjdk-25 | — |
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 16.04 LTS |
|---|---|
| openjdk-8 | Not affected |
| openjdk-9 | Ignored |
| openjdk-lts | — |
| openjdk-13 | — |
| openjdk-16 | — |
| openjdk-17 | — |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | — |
| openjdk-21-crac | — |
| openjdk-25 | — |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20,...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 16.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | Ignored |
| openjdk-lts | — |
| openjdk-13 | — |
| openjdk-16 | — |
| openjdk-17 | — |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | — |
| openjdk-21-crac | — |
| openjdk-25 | — |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20,...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 16.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | Ignored |
| openjdk-lts | — |
| openjdk-13 | — |
| openjdk-16 | — |
| openjdk-17 | — |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | — |
| openjdk-21-crac | — |
| openjdk-25 | — |
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive...
2 affected packages
docker.io, docker.io-app
| Package | 16.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | — |
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the...
1 affected package
kraken
| Package | 16.04 LTS |
|---|---|
| kraken | Needs evaluation |
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0...
1 affected package
hugo
| Package | 16.04 LTS |
|---|---|
| hugo | Needs evaluation |
libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte...
2 affected packages
libmodplug, gst-plugins-bad0.10
| Package | 16.04 LTS |
|---|---|
| libmodplug | Needs evaluation |
| gst-plugins-bad0.10 | — |