Search CVE reports
441 – 450 of 532 results
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
1 affected package
ocsinventory-agent
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ocsinventory-agent | — | — | — | — | — |
Some fixes available 1 of 4
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.
2 affected packages
fckeditor, moin
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| fckeditor | — | — | — | — | — |
| moin | — | — | — | — | — |
Some fixes available 1 of 3
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules,...
2 affected packages
fckeditor, moin
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| fckeditor | — | — | — | — | — |
| moin | — | — | — | — | — |
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
1 affected package
ocsinventory-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ocsinventory-server | — | — | — | — | Not affected |
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary...
1 affected package
libtorrent-rasterbar
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libtorrent-rasterbar | — | — | — | — | — |
The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.
1 affected package
ocsinventory-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ocsinventory-server | — | — | — | — | — |
Some fixes available 1 of 3
Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash)...
1 affected package
ctorrent
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ctorrent | — | — | — | — | — |
Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.
1 affected package
ocsinventory-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ocsinventory-server | — | — | — | — | — |
Some fixes available 34 of 74
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to...
14 affected packages
cups, cupsys, evince, gpdf, ipe...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cups | — | — | Not affected | Not affected | Not affected |
| cupsys | — | — | Not in release | Not in release | Not in release |
| evince | — | — | Not affected | Not affected | Not affected |
| gpdf | — | — | Not in release | Not in release | Not in release |
| ipe | — | — | Not affected | Not affected | Not affected |
| kdegraphics | — | — | Not in release | Not in release | Not in release |
| koffice | — | — | Not in release | Not in release | Not in release |
| libextractor | — | — | Not affected | Not affected | Not affected |
| pdfkit.framework | — | — | Not in release | Not in release | Not in release |
| pdftohtml | — | — | Not in release | Not in release | Not in release |
| poppler | — | — | Fixed | Fixed | Fixed |
| tetex-bin | — | — | Not in release | Not in release | Not in release |
| texlive-bin | — | — | Not affected | Not affected | Not affected |
| xpdf | — | — | Not affected | Not in release | Not affected |
Some fixes available 5 of 19
Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).
14 affected packages
cups, cupsys, evince, gpdf, ipe...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cups | — | — | — | — | — |
| cupsys | — | — | — | — | — |
| evince | — | — | — | — | — |
| gpdf | — | — | — | — | — |
| ipe | — | — | — | — | — |
| kdegraphics | — | — | — | — | — |
| koffice | — | — | — | — | — |
| libextractor | — | — | — | — | — |
| pdfkit.framework | — | — | — | — | — |
| pdftohtml | — | — | — | — | — |
| poppler | — | — | — | — | — |
| tetex-bin | — | — | — | — | — |
| texlive-bin | — | — | — | — | — |
| xpdf | — | — | — | — | — |