Search CVE reports
891 – 900 of 56918 results
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path...
2 affected packages
sos, sosreport
| Package | 16.04 LTS |
|---|---|
| sos | — |
| sosreport | Needs evaluation |
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.
1 affected package
check-mk
| Package | 16.04 LTS |
|---|---|
| check-mk | Needs evaluation |
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause...
1 affected package
389-ds-base
| Package | 16.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer...
1 affected package
file-roller
| Package | 16.04 LTS |
|---|---|
| file-roller | Needs evaluation |
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |