Search CVE reports
1711 – 1720 of 35604 results
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote....
1 affected package
miniupnpd
| Package | 24.04 LTS |
|---|---|
| miniupnpd | Needs evaluation |
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can...
1 affected package
radare2
| Package | 24.04 LTS |
|---|---|
| radare2 | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters,...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
Not in release
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the...
1 affected package
dolibarr
| Package | 24.04 LTS |
|---|---|
| dolibarr | Not in release |
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While...
1 affected package
xrdp
| Package | 24.04 LTS |
|---|---|
| xrdp | Needs evaluation |
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the...
2 affected packages
firebird3.0, firebird4.0
| Package | 24.04 LTS |
|---|---|
| firebird3.0 | Needs evaluation |
| firebird4.0 | Not in release |