Search CVE reports
1861 – 1870 of 49226 results
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may...
1 affected package
vlc
| Package | 20.04 LTS |
|---|---|
| vlc | Needs evaluation |
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with...
1 affected package
vlc
| Package | 20.04 LTS |
|---|---|
| vlc | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |