Search CVE reports
11 – 20 of 53368 results
(An issue in MongoDB Server could allow an authenticated user with a li ...)
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
(An issue in MongoDB Server's aggregation framework could allow an auth ...)
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
(MongoDB Server's handling of a Queryable Encryption maintenance operat ...)
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...
1 affected package
dnsmasq
| Package | 16.04 LTS |
|---|---|
| dnsmasq | Needs evaluation |
(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
1 affected package
ruby-rails-html-sanitizer
| Package | 16.04 LTS |
|---|---|
| ruby-rails-html-sanitizer | Needs evaluation |
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method....
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |