Search CVE reports
16501 – 16510 of 48193 results
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
1 affected package
curl
| Package | 16.04 LTS |
|---|---|
| curl | Not affected |
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different...
1 affected package
curl
| Package | 16.04 LTS |
|---|---|
| curl | Fixed |
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
1 affected package
chromium-browser
| Package | 16.04 LTS |
|---|---|
| chromium-browser | Ignored |
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
1 affected package
chromium-browser
| Package | 16.04 LTS |
|---|---|
| chromium-browser | Ignored |
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction....
1 affected package
chromium-browser
| Package | 16.04 LTS |
|---|---|
| chromium-browser | Ignored |
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction....
1 affected package
chromium-browser
| Package | 16.04 LTS |
|---|---|
| chromium-browser | Ignored |
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
| Package | 16.04 LTS |
|---|---|
| chromium-browser | Ignored |
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no...
1 affected package
bluez
| Package | 16.04 LTS |
|---|---|
| bluez | Fixed |
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for...
3 affected packages
golang-1.19, golang-1.20, golang-1.21
| Package | 16.04 LTS |
|---|---|
| golang-1.19 | Ignored |
| golang-1.20 | Ignored |
| golang-1.21 | Ignored |
A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause...
3 affected packages
golang-1.19, golang-1.20, golang-1.21
| Package | 16.04 LTS |
|---|---|
| golang-1.19 | Ignored |
| golang-1.20 | Ignored |
| golang-1.21 | Ignored |