Search CVE reports
71 – 80 of 36055 results
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...
1 affected package
sudo
| Package | 26.04 LTS |
|---|---|
| sudo | Needs evaluation |
Not in release
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear...
6 affected packages
rubygems, ruby2.3, ruby2.5, ruby2.7, ruby3.0, jruby
| Package | 26.04 LTS |
|---|---|
| rubygems | Needs evaluation |
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Not in release |
| jruby | Needs evaluation |
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by...
1 affected package
node-qs
| Package | 26.04 LTS |
|---|---|
| node-qs | Needs evaluation |
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |