Search CVE reports
2471 – 2480 of 38328 results
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be...
1 affected package
asterisk
Package | 18.04 LTS |
---|---|
asterisk | Needs evaluation |
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE...
1 affected package
asterisk
Package | 18.04 LTS |
---|---|
asterisk | Needs evaluation |
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read...
1 affected package
pglogical
Package | 18.04 LTS |
---|---|
pglogical | Not affected |
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
1 affected package
check-mk
Package | 18.04 LTS |
---|---|
check-mk | Needs evaluation |
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.
1 affected package
taglib
Package | 18.04 LTS |
---|---|
taglib | Needs evaluation |
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this...
1 affected package
poedit
Package | 18.04 LTS |
---|---|
poedit | Not affected |
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this...
1 affected package
gst-plugins-bad1.0
Package | 18.04 LTS |
---|---|
gst-plugins-bad1.0 | Vulnerable |
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability...
1 affected package
gstreamer1.0
Package | 18.04 LTS |
---|---|
gstreamer1.0 | Not affected |
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular...
4 affected packages
openssl, openssl1.0, nodejs, edk2
Package | 18.04 LTS |
---|---|
openssl | Not affected |
openssl1.0 | Not affected |
nodejs | Not affected |
edk2 | Not affected |
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable...
2 affected packages
modsecurity, modsecurity-apache
Package | 18.04 LTS |
---|---|
modsecurity | — |
modsecurity-apache | Fixed |