Search CVE reports
16451 – 16460 of 48196 results
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
1 affected package
shiro
| Package | 16.04 LTS |
|---|---|
| shiro | Ignored |
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the...
1 affected package
asterisk
| Package | 16.04 LTS |
|---|---|
| asterisk | Needs evaluation |
jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.
1 affected package
jq
| Package | 16.04 LTS |
|---|---|
| jq | Not affected |
Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are allowed. One of the validations is that the SVG document does not reference itself....
1 affected package
php-dompdf
| Package | 16.04 LTS |
|---|---|
| php-dompdf | Not affected |
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
1 affected package
jq
| Package | 16.04 LTS |
|---|---|
| jq | Not affected |
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue....
1 affected package
glpi
| Package | 16.04 LTS |
|---|---|
| glpi | Needs evaluation |
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a...
1 affected package
glpi
| Package | 16.04 LTS |
|---|---|
| glpi | Needs evaluation |
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue.
1 affected package
glpi
| Package | 16.04 LTS |
|---|---|
| glpi | Needs evaluation |
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
1 affected package
tinyxml
| Package | 16.04 LTS |
|---|---|
| tinyxml | Fixed |
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
1 affected package
check-mk
| Package | 16.04 LTS |
|---|---|
| check-mk | Needs evaluation |