Search CVE reports
981 – 990 of 46705 results
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or...
1 affected package
cyrus-imapd
| Package | 24.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which...
1 affected package
cyrus-imapd
| Package | 24.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's...
1 affected package
cyrus-imapd
| Package | 24.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue...
1 affected package
activemq
| Package | 24.04 LTS |
|---|---|
| activemq | Needs evaluation |
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...
1 affected package
keepass2
| Package | 24.04 LTS |
|---|---|
| keepass2 | Needs evaluation |
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching...
1 affected package
bubblewrap
| Package | 24.04 LTS |
|---|---|
| bubblewrap | Vulnerable |