Search CVE reports
901 – 910 of 56918 results
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g....
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking...
1 affected package
adminer
| Package | 16.04 LTS |
|---|---|
| adminer | Needs evaluation |
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Not affected |
| edk2-hwe | — |
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Not affected |
| edk2-hwe | — |
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Not affected |
| edk2-hwe | — |
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Not affected |
| edk2-hwe | — |
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Not affected |
| edk2-hwe | — |