Search CVE reports
1781 – 1790 of 49194 results
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects,...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled...
1 affected package
gvfs
| Package | 20.04 LTS |
|---|---|
| gvfs | Needs evaluation |
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 20.04 LTS |
|---|---|
| node-cookies | Needs evaluation |
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript...
1 affected package
evolution
| Package | 20.04 LTS |
|---|---|
| evolution | Needs evaluation |
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided...
1 affected package
pcs
| Package | 20.04 LTS |
|---|---|
| pcs | Not affected |