Search CVE reports
391 – 400 of 40627 results
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
1 affected package
putty
| Package | 22.04 LTS |
|---|---|
| putty | Needs evaluation |
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
1 affected package
putty
| Package | 22.04 LTS |
|---|---|
| putty | Needs evaluation |
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to...
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only...
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or...
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later,...
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
1 affected package
roundcube
| Package | 22.04 LTS |
|---|---|
| roundcube | Needs evaluation |
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
1 affected package
roundcube
| Package | 22.04 LTS |
|---|---|
| roundcube | Needs evaluation |
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
1 affected package
roundcube
| Package | 22.04 LTS |
|---|---|
| roundcube | Needs evaluation |
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
1 affected package
roundcube
| Package | 22.04 LTS |
|---|---|
| roundcube | Needs evaluation |