Search CVE reports
761 – 770 of 26567 results
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user...
1 affected package
zabbix
| Package | 26.04 LTS |
|---|---|
| zabbix | Needs evaluation |
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
1 affected package
paramiko
| Package | 26.04 LTS |
|---|---|
| paramiko | Needs evaluation |
[Unknown description]
1 affected package
qemu
| Package | 26.04 LTS |
|---|---|
| qemu | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and...
1 affected package
jupyter-server
| Package | 26.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because...
1 affected package
jupyter-server
| Package | 26.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed...
1 affected package
proftpd-dfsg
| Package | 26.04 LTS |
|---|---|
| proftpd-dfsg | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access...
1 affected package
jupyter-server
| Package | 26.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which...
1 affected package
ironic
| Package | 26.04 LTS |
|---|---|
| ironic | Needs evaluation |
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the...
1 affected package
modsecurity
| Package | 26.04 LTS |
|---|---|
| modsecurity | Needs evaluation |
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a...
1 affected package
horizon
| Package | 26.04 LTS |
|---|---|
| horizon | Needs evaluation |