Search CVE reports


Toggle filters

501 – 510 of 558 results


CVE-2008-5906

Medium priority

Some fixes available 3 of 4

Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.

3 affected packages

ktorrent, ktorrent-kde4, ktorrent2.2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ktorrent — — — — —
ktorrent-kde4 — — — — —
ktorrent2.2 — — — — —
Show less packages

CVE-2008-5905

Medium priority

Some fixes available 3 of 4

The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.

3 affected packages

ktorrent, ktorrent-kde4, ktorrent2.2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ktorrent — — — — —
ktorrent-kde4 — — — — —
ktorrent2.2 — — — — —
Show less packages

CVE-2008-5398

Low priority
Ignored

Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2008-5397

Low priority
Ignored

Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2008-3568

Medium priority
Not affected

Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor — — — — —
Show less packages

CVE-2008-2950

Low priority

Some fixes available 2 of 13

The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf — — — — —
ipe — — — — —
kdegraphics — — — — —
koffice — — — — —
libextractor — — — — —
pdfkit.framework — — — — —
pdftohtml — — — — —
poppler — — — — —
tetex-bin — — — — —
texlive-bin — — — — —
xpdf — — — — —
Show all 11 packages Show less packages

CVE-2008-1693

Medium priority

Some fixes available 10 of 26

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf — — — — —
ipe — — — — —
kdegraphics — — — — —
koffice — — — — —
libextractor — — — — —
pdfkit.framework — — — — —
pdftohtml — — — — —
poppler — — — — —
tetex-bin — — — — —
texlive-bin — — — — —
xpdf — — — — —
Show all 11 packages Show less packages

CVE-2008-0646

Low priority
Ignored

The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service...

3 affected packages

deluge, deluge-torrent, libtorrent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
deluge — — — — —
deluge-torrent — — — — —
libtorrent — — — — —
Show less packages

CVE-2007-6465

Low priority
Not affected

Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia before 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G,...

1 affected package

ganglia-monitor-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ganglia-monitor-core — — — — —
Show less packages

CVE-2007-5393

Medium priority

Some fixes available 25 of 36

Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.

13 affected packages

cups, cupsys, gpdf, ipe, kdegraphics...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups — — — — —
cupsys — — — — —
gpdf — — — — —
ipe — — — — —
kdegraphics — — — — —
koffice — — — — —
libextractor — — — — —
pdfkit.framework — — — — —
pdftohtml — — — — —
poppler — — — — —
tetex-bin — — — — —
texlive-bin — — — — —
xpdf — — — — —
Show all 13 packages Show less packages