Search CVE reports
451 – 460 of 47154 results
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
1 affected package
glpi
| Package | 16.04 LTS |
|---|---|
| glpi | Needs evaluation |
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access...
1 affected package
glpi
| Package | 16.04 LTS |
|---|---|
| glpi | Needs evaluation |
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...
1 affected package
libxml2
| Package | 16.04 LTS |
|---|---|
| libxml2 | Fixed |
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...
1 affected package
libxml2
| Package | 16.04 LTS |
|---|---|
| libxml2 | Fixed |
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...
1 affected package
libxml2
| Package | 16.04 LTS |
|---|---|
| libxml2 | Fixed |
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap...
2 affected packages
eglibc, glibc
| Package | 16.04 LTS |
|---|---|
| eglibc | — |
| glibc | Not affected |