Search CVE reports
21 – 30 of 51 results
Some fixes available 4 of 24
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of...
3 affected packages
collada2gltf, pandas, ujson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| collada2gltf | Not in release | Needs evaluation | Not in release | Needs evaluation |
| pandas | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ujson | Not affected | Fixed | Fixed | Fixed |
Some fixes available 3 of 5
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor...
1 affected package
kopanocore
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| kopanocore | Not in release | Fixed | Fixed | Fixed |
Some fixes available 5 of 6
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
1 affected package
libpano13
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| libpano13 | Not affected | Fixed | Fixed | Fixed |
Some fixes available 4 of 21
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
2 affected packages
pandas, ujson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| pandas | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ujson | Not affected | Fixed | Fixed | Fixed |
The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
1 affected package
libcpan-checksums-perl
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| libcpan-checksums-perl | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
Some fixes available 4 of 6
The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
1 affected package
cpanminus
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cpanminus | Not affected | Fixed | Fixed | Fixed |
Some fixes available 4 of 7
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
1 affected package
libpano13
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| libpano13 | Not affected | Fixed | Fixed | Fixed |
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
1 affected package
kopanocore
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| kopanocore | Not in release | Vulnerable | Vulnerable | Vulnerable |
Some fixes available 1 of 14
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g.,...
1 affected package
libetpan
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| libetpan | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue...
1 affected package
kopanocore
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| kopanocore | — | — | Not affected | Not affected |