Search CVE reports
71 – 80 of 31371 results
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13,...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 22.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1,...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 22.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141,...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 22.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
Firefox executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 22.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141,...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 22.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR <...
9 affected packages
mozjs68, firefox, thunderbird, mozjs38, mozjs52...
Package | 22.04 LTS |
---|---|
mozjs68 | Not in release |
firefox | Not affected |
thunderbird | Vulnerable |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs78 | Ignored |
mozjs91 | Ignored |
mozjs102 | Ignored |
mozjs115 | Not in release |
In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
1 affected package
jakarta-mail
Package | 22.04 LTS |
---|---|
jakarta-mail | Needs evaluation |
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument...
1 affected package
gpac
Package | 22.04 LTS |
---|---|
gpac | Needs evaluation |
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3,...
1 affected package
node-form-data
Package | 22.04 LTS |
---|---|
node-form-data | Needs evaluation |
[NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c)]
2 affected packages
ffmpeg, libav
Package | 22.04 LTS |
---|---|
ffmpeg | Needs evaluation |
libav | Not in release |