Search CVE reports
201 – 210 of 52206 results
Not in release
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go...
1 affected package
dasel
| Package | 22.04 LTS |
|---|---|
| dasel | Not in release |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...
1 affected package
ntopng
| Package | 22.04 LTS |
|---|---|
| ntopng | Needs evaluation |
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was...
1 affected package
mina2
| Package | 22.04 LTS |
|---|---|
| mina2 | Needs evaluation |
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...
1 affected package
fetchmail
| Package | 22.04 LTS |
|---|---|
| fetchmail | Needs evaluation |
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...
1 affected package
dogtag-pki
| Package | 22.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...
1 affected package
bleachbit
| Package | 22.04 LTS |
|---|---|
| bleachbit | Not affected |
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
1 affected package
libxrender
| Package | 22.04 LTS |
|---|---|
| libxrender | Needs evaluation |