Search CVE reports
851 – 860 of 48899 results
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable...
2 affected packages
squid, squid3
| Package | 16.04 LTS |
|---|---|
| squid | — |
| squid3 | Needs evaluation |
Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of...
2 affected packages
squid, squid3
| Package | 16.04 LTS |
|---|---|
| squid | — |
| squid3 | Needs evaluation |
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This...
2 affected packages
squid, squid3
| Package | 16.04 LTS |
|---|---|
| squid | — |
| squid3 | Needs evaluation |
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary...
1 affected package
libplack-middleware-session-perl
| Package | 16.04 LTS |
|---|---|
| libplack-middleware-session-perl | Needs evaluation |
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
1 affected package
osslsigncode
| Package | 16.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
1 affected package
plexus-utils
| Package | 16.04 LTS |
|---|---|
| plexus-utils | Needs evaluation |
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
1 affected package
fontconfig
| Package | 16.04 LTS |
|---|---|
| fontconfig | Not affected |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn...
1 affected package
gitlab
| Package | 16.04 LTS |
|---|---|
| gitlab | Ignored |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge...
1 affected package
gitlab
| Package | 16.04 LTS |
|---|---|
| gitlab | Ignored |
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the...
2 affected packages
requests, python-pip
| Package | 16.04 LTS |
|---|---|
| requests | Needs evaluation |
| python-pip | Needs evaluation |