Search CVE reports
671 – 680 of 53354 results
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to...
1 affected package
sssd
| Package | 16.04 LTS |
|---|---|
| sssd | Needs evaluation |
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal...
1 affected package
popt
| Package | 16.04 LTS |
|---|---|
| popt | Needs evaluation |
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates,...
1 affected package
python-cryptography
| Package | 16.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a...
1 affected package
python-cryptography
| Package | 16.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a...
1 affected package
python-cryptography
| Package | 16.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and...
1 affected package
angular.js
| Package | 16.04 LTS |
|---|---|
| angular.js | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in...
1 affected package
angular.js
| Package | 16.04 LTS |
|---|---|
| angular.js | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters,...
1 affected package
angular.js
| Package | 16.04 LTS |
|---|---|
| angular.js | Needs evaluation |
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has...
1 affected package
tar
| Package | 16.04 LTS |
|---|---|
| tar | Needs evaluation |
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A...
1 affected package
tar
| Package | 16.04 LTS |
|---|---|
| tar | Needs evaluation |