Search CVE reports
41 – 43 of 43 results
Some fixes available 1 of 56
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory...
10 affected packages
eet, efl, firefox, grub2, gtkwave...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| eet | — | — | Not in release | Not in release | Not in release |
| efl | — | — | Not affected | Not affected | Not affected |
| firefox | — | — | Not affected | Not in release | Not affected |
| grub2 | — | — | Not affected | Not affected | Not affected |
| gtkwave | — | — | Not affected | Not affected | Not affected |
| lz4 | — | — | Not affected | Not affected | Not affected |
| php-horde-lz4 | — | — | Not in release | Not in release | Not affected |
| pytables | — | — | Not affected | Not affected | Not affected |
| thunderbird | — | — | Not affected | Not in release | Not affected |
| zfsutils | — | — | Not in release | Not in release | Not in release |
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
2 affected packages
horde3, php-horde-util
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| horde3 | — | — | — | — | — |
| php-horde-util | — | — | — | — | — |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1 affected package
php-horde-kronolith
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-horde-kronolith | — | — | — | — | — |