Search CVE reports
1 – 10 of 49194 results
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media...
1 affected package
php-getid3
| Package | 20.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject...
1 affected package
php-getid3
| Package | 20.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 20.04 LTS |
|---|---|
| expat | Needs evaluation |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | — |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | — |
| cableswig | — |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | — |
| smart | — |
| firefox | — |
| thunderbird | — |
| libxmltok | Needs evaluation |
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name)...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 20.04 LTS |
|---|---|
| kamailio | Needs evaluation |