Search CVE reports
331 – 340 of 32959 results
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links...
1 affected package
onionshare
| Package | 26.04 LTS |
|---|---|
| onionshare | Needs evaluation |
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or...
1 affected package
node-ajv
| Package | 26.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing...
1 affected package
gnome-remote-desktop
| Package | 26.04 LTS |
|---|---|
| gnome-remote-desktop | Needs evaluation |
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the...
2 affected packages
commons-httpclient, httpcomponents-client
| Package | 26.04 LTS |
|---|---|
| commons-httpclient | Needs evaluation |
| httpcomponents-client | Needs evaluation |
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content...
1 affected package
php-codeigniter-framework
| Package | 26.04 LTS |
|---|---|
| php-codeigniter-framework | Needs evaluation |
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal...
1 affected package
php-codeigniter-framework
| Package | 26.04 LTS |
|---|---|
| php-codeigniter-framework | Needs evaluation |
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled...
1 affected package
php-codeigniter-framework
| Package | 26.04 LTS |
|---|---|
| php-codeigniter-framework | Needs evaluation |
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these...
1 affected package
php-codeigniter-framework
| Package | 26.04 LTS |
|---|---|
| php-codeigniter-framework | Needs evaluation |