Search CVE reports


Toggle filters

31 – 40 of 87 results


CVE-2018-11805

Medium priority
Fixed

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we...

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2018-11781

Low priority
Fixed

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2018-11780

Medium priority
Fixed

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2018-10380

Medium priority
Vulnerable

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

2 affected packages

kwallet-pam, pam-kwallet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kwallet-pam Not affected Not affected Not affected Vulnerable
pam-kwallet Not in release Not in release Not in release Not in release
Show less packages

CVE-2017-15705

Medium priority
Fixed

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts....

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2017-12197

Medium priority
Fixed

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access...

1 affected package

libpam4j

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam4j
Show less packages

CVE-2017-11737

Medium priority
Not affected

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

1 affected package

rspamd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rspamd Not affected Not in release
Show less packages

CVE-2016-4422

High priority

Some fixes available 3 of 4

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.

1 affected package

libpam-sshauth

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-sshauth
Show less packages

CVE-2016-20014

Low priority
Needs evaluation

In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.

1 affected package

libpam-tacplus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-tacplus Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2015-9542

Medium priority
Fixed

add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an...

1 affected package

libpam-radius-auth

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-radius-auth Fixed
Show less packages