Search CVE reports
1 – 10 of 35399 results
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be...
1 affected package
asterisk
Package | 18.04 LTS |
---|---|
asterisk | Needs evaluation |
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE...
1 affected package
asterisk
Package | 18.04 LTS |
---|---|
asterisk | Needs evaluation |
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this...
1 affected package
poedit
Package | 18.04 LTS |
---|---|
poedit | Not affected |
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this...
1 affected package
gst-plugins-bad1.0
Package | 18.04 LTS |
---|---|
gst-plugins-bad1.0 | Needs evaluation |
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
1 affected package
check-mk
Package | 18.04 LTS |
---|---|
check-mk | Needs evaluation |
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability...
1 affected package
gstreamer1.0
Package | 18.04 LTS |
---|---|
gstreamer1.0 | Needs evaluation |
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read...
1 affected package
pglogical
Package | 18.04 LTS |
---|---|
pglogical | Not affected |
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.
1 affected package
taglib
Package | 18.04 LTS |
---|---|
taglib | Needs evaluation |
Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability...
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body,...
2 affected packages
libsoup2.4, libsoup3
Package | 18.04 LTS |
---|---|
libsoup2.4 | Vulnerable |
libsoup3 | — |