Search CVE reports
781 – 790 of 36929 results
[Stack Buffer Overflow in radvdump Route Information Option Parser]
1 affected package
radvd
| Package | 24.04 LTS |
|---|---|
| radvd | Needs evaluation |
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path...
1 affected package
starlette
| Package | 24.04 LTS |
|---|---|
| starlette | Needs evaluation |
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
Denial of service against AD DC WINS server
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Fixed |
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or...
1 affected package
samba
| Package | 24.04 LTS |
|---|---|
| samba | Not affected |