Search CVE reports


Toggle filters

1221 – 1230 of 1764 results


CVE-2015-1042

Medium priority
Ignored

The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a ":/"...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2014-5332

High priority
Ignored

Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_CREATE IOCTL call, which triggers a use-after-free error, as demonstrated by using a race condition to escape...

30 affected packages

linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux
linux-armadaxp
linux-aws
linux-ec2
linux-flo
linux-fsl-imx51
linux-gke
linux-goldfish
linux-grouper
linux-hwe
linux-hwe-edge
linux-linaro-omap
linux-linaro-shared
linux-linaro-vexpress
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-lts-trusty
linux-lts-utopic
linux-lts-vivid
linux-lts-wily
linux-lts-xenial
linux-maguro
linux-mako
linux-manta
linux-mvl-dove
linux-qcm-msm
linux-raspi2
linux-snapdragon
linux-ti-omap4
Show all 30 packages Show less packages

CVE-2015-1465

Medium priority

Some fixes available 4 of 15

The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a...

23 affected packages

linux-goldfish, linux-grouper, linux-maguro, linux-mako, linux-manta...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux-goldfish
linux-grouper
linux-maguro
linux-mako
linux-manta
linux-flo
linux-lts-vivid
linux
linux-armadaxp
linux-ec2
linux-fsl-imx51
linux-linaro-omap
linux-linaro-shared
linux-linaro-vexpress
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-lts-trusty
linux-lts-utopic
linux-mvl-dove
linux-qcm-msm
linux-raspi2
linux-ti-omap4
Show all 23 packages Show less packages

CVE-2014-9573

Medium priority
Ignored

SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE privileges to execute arbitrary SQL commands via the MANTIS_MANAGE_USERS_COOKIE cookie.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2014-9572

Low priority
Ignored

MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2014-9571

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2015-0239

High priority

Some fixes available 7 of 36

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS...

30 affected packages

linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux
linux-armadaxp
linux-aws
linux-ec2
linux-flo
linux-fsl-imx51
linux-gke
linux-goldfish
linux-grouper
linux-hwe
linux-hwe-edge
linux-linaro-omap
linux-linaro-shared
linux-linaro-vexpress
linux-lts-quantal
linux-lts-raring
linux-lts-saucy
linux-lts-trusty
linux-lts-utopic
linux-lts-vivid
linux-lts-wily
linux-lts-xenial
linux-maguro
linux-mako
linux-manta
linux-mvl-dove
linux-qcm-msm
linux-raspi2
linux-snapdragon
linux-ti-omap4
Show all 30 packages Show less packages

CVE-2014-9272

Medium priority
Ignored

The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2014-9271

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to...

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages

CVE-2014-9269

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.

1 affected package

mantis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mantis
Show less packages