Search CVE reports
1931 – 1940 of 47976 results
nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim enters...
1 affected package
nnn
| Package | 20.04 LTS |
|---|---|
| nnn | Needs evaluation |
nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0....
1 affected package
nnn
| Package | 20.04 LTS |
|---|---|
| nnn | Needs evaluation |
nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of...
1 affected package
nnn
| Package | 20.04 LTS |
|---|---|
| nnn | Needs evaluation |
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on...
1 affected package
cockpit
| Package | 20.04 LTS |
|---|---|
| cockpit | Needs evaluation |
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally...
1 affected package
libnet-oauth-perl
| Package | 20.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is...
1 affected package
libnet-oauth-perl
| Package | 20.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null...
1 affected package
busybox
| Package | 20.04 LTS |
|---|---|
| busybox | Needs evaluation |
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a...
1 affected package
vim
| Package | 20.04 LTS |
|---|---|
| vim | Fixed |
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when...
1 affected package
libheif
| Package | 20.04 LTS |
|---|---|
| libheif | Not affected |
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the...
1 affected package
mediawiki
| Package | 20.04 LTS |
|---|---|
| mediawiki | Needs evaluation |