Search CVE reports
261 – 270 of 56791 results
[Unknown description]
1 affected package
openvpn
| Package | 16.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 16.04 LTS |
|---|---|
| openvpn | Needs evaluation |
A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is...
1 affected package
ocsinventory-server
| Package | 16.04 LTS |
|---|---|
| ocsinventory-server | Needs evaluation |
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can...
1 affected package
ocsinventory-server
| Package | 16.04 LTS |
|---|---|
| ocsinventory-server | Needs evaluation |
SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator...
1 affected package
ocsinventory-server
| Package | 16.04 LTS |
|---|---|
| ocsinventory-server | Needs evaluation |
SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper...
1 affected package
ocsinventory-server
| Package | 16.04 LTS |
|---|---|
| ocsinventory-server | Needs evaluation |
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their...
1 affected package
ocsinventory-server
| Package | 16.04 LTS |
|---|---|
| ocsinventory-server | Needs evaluation |
A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial...
1 affected package
gfs2-utils
| Package | 16.04 LTS |
|---|---|
| gfs2-utils | Needs evaluation |
A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive...
1 affected package
gfs2-utils
| Package | 16.04 LTS |
|---|---|
| gfs2-utils | Needs evaluation |
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to...
1 affected package
gfs2-utils
| Package | 16.04 LTS |
|---|---|
| gfs2-utils | Needs evaluation |