Search CVE reports
321 – 330 of 50075 results
(A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP ...)
2 affected packages
ffmpeg, libav
| Package | 22.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
(The API is prone to XML external entity (XXE) injection. By default, X ...)
1 affected package
libnanoxml2-java
| Package | 22.04 LTS |
|---|---|
| libnanoxml2-java | Needs evaluation |
(A flaw was found in FreeIPA. An unauthenticated remote attacker could ...)
1 affected package
freeipa
| Package | 22.04 LTS |
|---|---|
| freeipa | Needs evaluation |
VPATCH BYPARAM double-free: An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
Sieve mailbox existence oracle: An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
Mailbox/set let sharee change special-use role on shared mailboxes: An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
CalDAV/CardDAV multiget bypasses per-href ACL: An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
JMAP email-header blob ID out-of-bounds index: An authenticated user could attempt to download a specially crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
JMAP snooze bypasses destination-mailbox ACL: An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
(A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)
1 affected package
glib2.0
| Package | 22.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |