Search CVE reports


Toggle filters

101 – 110 of 488 results


CVE-2022-30187

Medium priority
Vulnerable

Azure Storage Library Information Disclosure Vulnerability

2 affected packages

python-azure, python-azure-storage

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-azure Not affected Vulnerable Not affected Not affected
python-azure-storage Not in release Not in release Ignored Ignored
Show less packages

CVE-2022-33070

Medium priority

Some fixes available 10 of 87

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

9 affected packages

argyll, ccextractor, libgadu, libpg-query, libsignal-protocol-c...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
argyll Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ccextractor Needs evaluation Needs evaluation Needs evaluation
libgadu Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libpg-query Needs evaluation Needs evaluation
libsignal-protocol-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ocserv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pidgin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
protobuf-c Fixed Fixed Fixed Needs evaluation
sudo Not affected Fixed Not affected Not affected
Show all 9 packages Show less packages

CVE-2021-43177

Medium priority

Some fixes available 2 of 5

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector:...

1 affected package

ruby-devise-two-factor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-devise-two-factor Not affected Fixed Fixed Not in release
Show less packages

CVE-2022-24803

Medium priority
Needs evaluation

Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary...

1 affected package

ruby-asciidoctor-include-ext

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-asciidoctor-include-ext Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24729

Low priority
Needs evaluation

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator...

4 affected packages

request-tracker4, ckeditor, ckeditor3, ldap-account-manager

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24728

Medium priority

Some fixes available 4 of 42

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Fixed Fixed Fixed
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24614

Medium priority
Needs evaluation

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a...

1 affected package

libmetadata-extractor-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmetadata-extractor-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24613

Low priority
Needs evaluation

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services...

1 affected package

libmetadata-extractor-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmetadata-extractor-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-23853

Medium priority
Needs evaluation

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it...

2 affected packages

kate, ktexteditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kate Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ktexteditor Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-21363

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network...

1 affected package

mysql-connector-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Needs evaluation
Show less packages