Search CVE reports
1071 – 1080 of 51201 results
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file,...
5 affected packages
tiff, qtwebengine-opensource-src, texmaker, gdal, neuron
| Package | 22.04 LTS |
|---|---|
| tiff | Needs evaluation |
| qtwebengine-opensource-src | Needs evaluation |
| texmaker | Needs evaluation |
| gdal | Not affected |
| neuron | Needs evaluation |
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
1 affected package
orthanc
| Package | 22.04 LTS |
|---|---|
| orthanc | Needs evaluation |
Not in release
Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell...
1 affected package
puppetserver
| Package | 22.04 LTS |
|---|---|
| puppetserver | Not in release |
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place —...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...
1 affected package
node-compression
| Package | 22.04 LTS |
|---|---|
| node-compression | Needs evaluation |