Search CVE reports
551 – 560 of 50598 results
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
4 affected packages
atril, evince, evince-gtk3, papers
| Package | 16.04 LTS |
|---|---|
| atril | — |
| evince | Needs evaluation |
| evince-gtk3 | — |
| papers | — |
[Heap OOB Read in VLAN Decapsulation memmove]
2 affected packages
lldpd, openvswitch
| Package | 16.04 LTS |
|---|---|
| lldpd | — |
| openvswitch | Needs evaluation |
Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could...
1 affected package
unbound
| Package | 16.04 LTS |
|---|---|
| unbound | Needs evaluation |
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with...
1 affected package
unbound
| Package | 16.04 LTS |
|---|---|
| unbound | Needs evaluation |
[Unknown description]
1 affected package
vim
| Package | 16.04 LTS |
|---|---|
| vim | Vulnerable |
Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |