Search CVE reports
651 – 660 of 45011 results
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before...
2 affected packages
smarty3, smarty4
| Package | 20.04 LTS |
|---|---|
| smarty3 | Needs evaluation |
| smarty4 | — |
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...
1 affected package
libstb
| Package | 20.04 LTS |
|---|---|
| libstb | Needs evaluation |
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...
1 affected package
dracut
| Package | 20.04 LTS |
|---|---|
| dracut | Needs evaluation |
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE...
1 affected package
wordpress
| Package | 20.04 LTS |
|---|---|
| wordpress | Needs evaluation |
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...
1 affected package
libvirt
| Package | 20.04 LTS |
|---|---|
| libvirt | Vulnerable |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 20.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
| pdns | Needs evaluation |
| pdns-recursor | Needs evaluation |
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...
1 affected package
policycoreutils
| Package | 20.04 LTS |
|---|---|
| policycoreutils | Needs evaluation |
A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to...
1 affected package
p11-kit
| Package | 20.04 LTS |
|---|---|
| p11-kit | Needs evaluation |
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...
1 affected package
python-h2
| Package | 20.04 LTS |
|---|---|
| python-h2 | Needs evaluation |