Search CVE reports
11 – 20 of 46861 results
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files...
1 affected package
python-git
| Package | 22.04 LTS |
|---|---|
| python-git | Needs evaluation |
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an...
1 affected package
sblim-cmpi-base
| Package | 22.04 LTS |
|---|---|
| sblim-cmpi-base | Needs evaluation |
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link,...
1 affected package
sblim-sfcb
| Package | 22.04 LTS |
|---|---|
| sblim-sfcb | Needs evaluation |
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially...
1 affected package
sblim-sfcb
| Package | 22.04 LTS |
|---|---|
| sblim-sfcb | Needs evaluation |
Not in release
(fast-xml-parser allows users to process XML from JS object without C/C ...)
1 affected package
node-webfont
| Package | 22.04 LTS |
|---|---|
| node-webfont | Not in release |
(node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...)
1 affected package
node-tar
| Package | 22.04 LTS |
|---|---|
| node-tar | Needs evaluation |
(PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability ...)
1 affected package
postgis
| Package | 22.04 LTS |
|---|---|
| postgis | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(),...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
(gdu fails to strip terminal escape sequences from directory and file n ...)
1 affected package
gdu
| Package | 22.04 LTS |
|---|---|
| gdu | Needs evaluation |