Search CVE reports
11 – 20 of 51994 results
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...
1 affected package
rclone
| Package | 22.04 LTS |
|---|---|
| rclone | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 22.04 LTS |
|---|---|
| kamailio | Needs evaluation |
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...
2 affected packages
varnish, vinyl-cache
| Package | 22.04 LTS |
|---|---|
| varnish | Needs evaluation |
| vinyl-cache | Not in release |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...
1 affected package
blazar
| Package | 22.04 LTS |
|---|---|
| blazar | Not in release |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...
1 affected package
blazar
| Package | 22.04 LTS |
|---|---|
| blazar | Not in release |
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in...
1 affected package
node-deepmerge
| Package | 22.04 LTS |
|---|---|
| node-deepmerge | Needs evaluation |
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...
1 affected package
node-uri-js
| Package | 22.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...
1 affected package
node-got
| Package | 22.04 LTS |
|---|---|
| node-got | Needs evaluation |
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...
1 affected package
node-postcss
| Package | 22.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....
1 affected package
node-got
| Package | 22.04 LTS |
|---|---|
| node-got | Needs evaluation |