Search CVE reports
241 – 250 of 51437 results
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 22.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Vulnerable |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Ignored |
| mozjs91 | Ignored |
| mozjs102 | Ignored |
| mozjs115 | Not in release |
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 22.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Vulnerable |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Ignored |
| mozjs91 | Ignored |
| mozjs102 | Ignored |
| mozjs115 | Not in release |
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 22.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Vulnerable |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Ignored |
| mozjs91 | Ignored |
| mozjs102 | Ignored |
| mozjs115 | Not in release |
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated...
1 affected package
python-jwcrypto
| Package | 22.04 LTS |
|---|---|
| python-jwcrypto | Needs evaluation |
[Incomplete fix of CVE-2018-10900]
1 affected package
network-manager-vpnc
| Package | 22.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
[username newline injection reaches a root password helper]
1 affected package
network-manager-vpnc
| Package | 22.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
[credential newline injection permits local root code execution]
1 affected package
network-manager-fortisslvpn
| Package | 22.04 LTS |
|---|---|
| network-manager-fortisslvpn | Needs evaluation |
[profile data reaches root pppd pty shell]
1 affected package
network-manager-sstp
| Package | 22.04 LTS |
|---|---|
| network-manager-sstp | Needs evaluation |
[network-manager-iodine: Option confusion reaches iodine's pre-drop root shell]
1 affected package
network-manager-iodine
| Package | 22.04 LTS |
|---|---|
| network-manager-iodine | Needs evaluation |
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
1 affected package
chromium-browser
| Package | 22.04 LTS |
|---|---|
| chromium-browser | Not affected |