Search CVE reports
1601 – 1610 of 58108 results
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then,...
10 affected packages
golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...
| Package | 16.04 LTS |
|---|---|
| golang-1.17 | — |
| golang-1.20 | — |
| golang-1.21 | — |
| golang-1.22 | — |
| golang-1.23 | — |
| golang-1.24 | — |
| golang-1.25 | — |
| golang-1.26 | — |
| golang-1.27 | — |
| golang-defaults | Needs evaluation |
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell...
1 affected package
rpm
| Package | 16.04 LTS |
|---|---|
| rpm | Needs evaluation |
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in...
1 affected package
rpm
| Package | 16.04 LTS |
|---|---|
| rpm | Needs evaluation |
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...
1 affected package
freeipa
| Package | 16.04 LTS |
|---|---|
| freeipa | Needs evaluation |
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records...
1 affected package
libnet-dns-perl
| Package | 16.04 LTS |
|---|---|
| libnet-dns-perl | Needs evaluation |
[Unknown description]
2 affected packages
ansible, ansible-core
| Package | 16.04 LTS |
|---|---|
| ansible | Needs evaluation |
| ansible-core | — |
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer...
1 affected package
php-nrk-predis
| Package | 16.04 LTS |
|---|---|
| php-nrk-predis | Needs evaluation |