Search CVE reports
71 – 80 of 31984 results
readline.sh in socat through 1.8.0.1 relies on the /tmp/$USER/stderr2 file.
1 affected package
socat
Package | 18.04 LTS |
---|---|
socat | Needs evaluation |
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages,...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media....
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
Authentication bypass in CEPH RadosGW
1 affected package
ceph
Package | 18.04 LTS |
---|---|
ceph | Not affected |
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...
1 affected package
ruby-rails-html-sanitizer
Package | 18.04 LTS |
---|---|
ruby-rails-html-sanitizer | Needs evaluation |
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...
1 affected package
ruby-rails-html-sanitizer
Package | 18.04 LTS |
---|---|
ruby-rails-html-sanitizer | Needs evaluation |