Search CVE reports
21 – 30 of 52029 results
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...
1 affected package
ntopng
| Package | 22.04 LTS |
|---|---|
| ntopng | Needs evaluation |
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...
1 affected package
dogtag-pki
| Package | 22.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
Not in release
web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).
1 affected package
web2py
| Package | 22.04 LTS |
|---|---|
| web2py | Not in release |
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
1 affected package
xiphos
| Package | 22.04 LTS |
|---|---|
| xiphos | Needs evaluation |
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the...
1 affected package
libnet-idn-encode-perl
| Package | 22.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a...
1 affected package
libnet-idn-encode-perl
| Package | 22.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The...
1 affected package
erlang
| Package | 22.04 LTS |
|---|---|
| erlang | Needs evaluation |
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder...
1 affected package
erlang
| Package | 22.04 LTS |
|---|---|
| erlang | Needs evaluation |
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the...
1 affected package
consul
| Package | 22.04 LTS |
|---|---|
| consul | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Needs evaluation |