Search CVE reports


Toggle filters

91 – 100 of 490 results


CVE-2023-21971

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network...

1 affected package

mysql-connector-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28439

Medium priority
Vulnerable

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after...

4 affected packages

ldap-account-manager, request-tracker4, ckeditor, ckeditor3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Vulnerable Vulnerable Vulnerable
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-48110

Medium priority
Ignored

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation...

4 affected packages

ldap-account-manager, request-tracker4, ckeditor3, ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Not affected Not affected Not affected Not affected
request-tracker4 Not affected Not affected Not affected Not affected
ckeditor3 Not affected Not affected Not affected Not affected
ckeditor Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-0341

Medium priority
Fixed

A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6...

1 affected package

editorconfig-core

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
editorconfig-core Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-23589

Medium priority
Needs evaluation

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-22457

Medium priority
Needs evaluation

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-45907

Medium priority
Needs evaluation

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release Not in release
Show less packages

CVE-2022-36180

Medium priority
Needs evaluation

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS)...

1 affected package

fusiondirectory

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fusiondirectory Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-36179

Medium priority
Needs evaluation

Fusiondirectory 1.3 suffers from Improper Session Handling.

1 affected package

fusiondirectory

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fusiondirectory Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-39369

Medium priority

Some fixes available 4 of 9

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...

3 affected packages

php-cas, ocsinventory-server, moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-cas Not affected Fixed Fixed Ignored
ocsinventory-server Not affected Fixed Not affected Not affected
moodle Not in release Not in release Not in release Ignored
Show less packages