Search CVE reports
601 – 610 of 36740 results
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
Denial of service against AD DC WINS server
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Not affected |
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
1 affected package
putty
| Package | 24.04 LTS |
|---|---|
| putty | Needs evaluation |
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
1 affected package
putty
| Package | 24.04 LTS |
|---|---|
| putty | Needs evaluation |
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
1 affected package
putty
| Package | 24.04 LTS |
|---|---|
| putty | Needs evaluation |
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to...
1 affected package
shiro
| Package | 24.04 LTS |
|---|---|
| shiro | Needs evaluation |