Search CVE reports
101 – 110 of 43788 results
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the...
1 affected package
wordpress
| Package | 24.04 LTS |
|---|---|
| wordpress | Needs evaluation |
Not in release
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing...
1 affected package
deskflow
| Package | 24.04 LTS |
|---|---|
| deskflow | Not in release |
Not in release
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized...
1 affected package
freecad
| Package | 24.04 LTS |
|---|---|
| freecad | Not in release |
Not in release
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a...
1 affected package
freecad
| Package | 24.04 LTS |
|---|---|
| freecad | Not in release |
Not in release
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd...
1 affected package
freecad
| Package | 24.04 LTS |
|---|---|
| freecad | Not in release |
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer...
1 affected package
netatalk
| Package | 24.04 LTS |
|---|---|
| netatalk | Needs evaluation |
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU...
1 affected package
sqlparse
| Package | 24.04 LTS |
|---|---|
| sqlparse | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through...
1 affected package
glances
| Package | 24.04 LTS |
|---|---|
| glances | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators...
1 affected package
glances
| Package | 24.04 LTS |
|---|---|
| glances | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing...
1 affected package
glances
| Package | 24.04 LTS |
|---|---|
| glances | Needs evaluation |