Search CVE reports
1 – 10 of 41315 results
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be...
1 affected package
asterisk
Package | 16.04 LTS |
---|---|
asterisk | Needs evaluation |
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE...
1 affected package
asterisk
Package | 16.04 LTS |
---|---|
asterisk | Needs evaluation |
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this...
1 affected package
poedit
Package | 16.04 LTS |
---|---|
poedit | Not affected |
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this...
1 affected package
gst-plugins-bad1.0
Package | 16.04 LTS |
---|---|
gst-plugins-bad1.0 | Needs evaluation |
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
1 affected package
check-mk
Package | 16.04 LTS |
---|---|
check-mk | Needs evaluation |
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability...
1 affected package
gstreamer1.0
Package | 16.04 LTS |
---|---|
gstreamer1.0 | Needs evaluation |
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.
1 affected package
taglib
Package | 16.04 LTS |
---|---|
taglib | Needs evaluation |
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body,...
2 affected packages
libsoup2.4, libsoup3
Package | 16.04 LTS |
---|---|
libsoup2.4 | Vulnerable |
libsoup3 | — |
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456...
1 affected package
jq
Package | 16.04 LTS |
---|---|
jq | Vulnerable |
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under...
2 affected packages
containerd, containerd-app
Package | 16.04 LTS |
---|---|
containerd | Needs evaluation |
containerd-app | — |