Search CVE reports
941 – 950 of 52944 results
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was...
1 affected package
mina2
| Package | 22.04 LTS |
|---|---|
| mina2 | Needs evaluation |
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...
1 affected package
fetchmail
| Package | 22.04 LTS |
|---|---|
| fetchmail | Needs evaluation |
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...
1 affected package
dogtag-pki
| Package | 22.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...
1 affected package
bleachbit
| Package | 22.04 LTS |
|---|---|
| bleachbit | Not affected |
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
1 affected package
libxrender
| Package | 22.04 LTS |
|---|---|
| libxrender | Needs evaluation |
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
1 affected package
libx11
| Package | 22.04 LTS |
|---|---|
| libx11 | Needs evaluation |
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have...
2 affected packages
mina, mina2
| Package | 22.04 LTS |
|---|---|
| mina | Needs evaluation |
| mina2 | Needs evaluation |