Search CVE reports
901 – 910 of 43529 results
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
1 affected package
roundcube
| Package | 18.04 LTS |
|---|---|
| roundcube | Needs evaluation |
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
1 affected package
roundcube
| Package | 18.04 LTS |
|---|---|
| roundcube | Needs evaluation |
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
1 affected package
python-tornado
| Package | 18.04 LTS |
|---|---|
| python-tornado | Fixed |
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
1 affected package
sudo
| Package | 18.04 LTS |
|---|---|
| sudo | Not affected |
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when...
1 affected package
util-linux
| Package | 18.04 LTS |
|---|---|
| util-linux | Vulnerable |
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
2 affected packages
openssh, openssh-ssh1
| Package | 18.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...
1 affected package
ruby-rack
| Package | 18.04 LTS |
|---|---|
| ruby-rack | Not affected |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...
1 affected package
ruby-rack
| Package | 18.04 LTS |
|---|---|
| ruby-rack | Ignored |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling...
1 affected package
ruby-rack
| Package | 18.04 LTS |
|---|---|
| ruby-rack | Not affected |
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack...
1 affected package
ruby-rack
| Package | 18.04 LTS |
|---|---|
| ruby-rack | Ignored |