Search CVE reports
1 – 10 of 36000 results
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified....
1 affected package
golang-github-go-git-go-git
| Package | 22.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line...
1 affected package
unity
| Package | 22.04 LTS |
|---|---|
| unity | Needs evaluation |
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
1 affected package
roundcube
| Package | 22.04 LTS |
|---|---|
| roundcube | Needs evaluation |
Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version....
1 affected package
adminer
| Package | 22.04 LTS |
|---|---|
| adminer | Needs evaluation |
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the...
1 affected package
ruby-faraday
| Package | 22.04 LTS |
|---|---|
| ruby-faraday | Needs evaluation |
Not in release
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its...
1 affected package
check-mk
| Package | 22.04 LTS |
|---|---|
| check-mk | Not in release |
Crafted zones can lead to increased incoming network traffic.
1 affected package
pdns-recursor
| Package | 22.04 LTS |
|---|---|
| pdns-recursor | Needs evaluation |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 22.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Needs evaluation |
| freerdp3 | Not in release |
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files....
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
[shiro: Brute force attack possible to determine valid user names]
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |