Search CVE reports


Toggle filters

391 – 400 of 558 results


CVE-2014-4037

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor — — — — Not in release
Show less packages

CVE-2014-3004

Medium priority
Vulnerable

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

1 affected package

castor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
castor Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2014-0749

Medium priority

Some fixes available 2 of 4

Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.

1 affected package

torque

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torque — — — — Not in release
Show less packages

CVE-2013-7374

Medium priority
Fixed

The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter...

1 affected package

indicator-datetime

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
indicator-datetime — — — — —
Show less packages

CVE-2013-4472

Medium priority
Not affected

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe — — — — —
libextractor — — — — —
poppler — — — — —
xpdf — — — — —
Show less packages

CVE-2012-2250

Medium priority
Ignored

Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-2249

Medium priority
Ignored

Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2013-0340

Medium priority
Ignored

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption),...

40 affected packages

apache2, apr-util, audacity, ayttm, cableswig...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
apr-util — — — — —
audacity — — — — —
ayttm — — — — —
cableswig — — — — —
cadaver — — — — —
celementtree — — — — —
cmake — — — — —
coin3 — — — — —
expat — — — — —
gdcm — — — — —
ghostscript — — — — —
grmonitor — — — — —
insighttoolkit — — — — —
kompozer — — — — —
libparagui1.1 — — — — —
matanza — — — — —
paraview — — — — —
poco — — — — —
python-xml — — — — —
python2.4 — — — — —
python2.5 — — — — —
python2.6 — — — — —
simgear — — — — —
sitecopy — — — — —
smart — — — — —
swish-e — — — — —
tdom — — — — —
texlive-bin — — — — —
tla — — — — —
vnc4 — — — — —
vtk — — — — —
w3c-libwww — — — — —
wbxml2 — — — — —
wxwidgets2.6 — — — — —
wxwidgets2.8 — — — — —
wxwindows2.4 — — — — —
xmlrpc-c — — — — —
xotcl — — — — —
xulrunner — — — — —
Show all 40 packages Show less packages

CVE-2013-7295

Low priority
Ignored

Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2013-4495

Medium priority

Some fixes available 1 of 5

The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the...

1 affected package

torque

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torque — — — — —
Show less packages