Search CVE reports
321 – 330 of 46439 results
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without...
1 affected package
gh
| Package | 22.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content...
1 affected package
gh
| Package | 22.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or...
1 affected package
gh
| Package | 22.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As...
1 affected package
gh
| Package | 22.04 LTS |
|---|---|
| gh | Needs evaluation |
[Unknown description]
1 affected package
wordpress
| Package | 22.04 LTS |
|---|---|
| wordpress | Needs evaluation |
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...
1 affected package
libvirt
| Package | 22.04 LTS |
|---|---|
| libvirt | Needs evaluation |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 22.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
| pdns | Needs evaluation |
| pdns-recursor | Needs evaluation |
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...
1 affected package
policycoreutils
| Package | 22.04 LTS |
|---|---|
| policycoreutils | Needs evaluation |
A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to...
1 affected package
p11-kit
| Package | 22.04 LTS |
|---|---|
| p11-kit | Needs evaluation |
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead...
1 affected package
nltk
| Package | 22.04 LTS |
|---|---|
| nltk | Needs evaluation |