Search: "canonical"

158 CVEs found

OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data with...

Published: 2019-04-17
Products: 1
Vendors:
omniauth

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without ...

Published: 2019-04-17
Products: 1
Vendors:
cisco

A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to mat...

Published: 2019-04-23
Products: 5
Vendors:
canonical
CVE-2019-7304
9.8 CRITICAL

Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37....

Published: 2019-04-23
Products: 5
Vendors:
canonical

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofin...

Published: 2019-06-11
Products: 7
Vendors:
canonical freedesktop
CVE-2019-18978
5.3 MEDIUM

An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure t...

Published: 2019-11-14
Products: 5
Vendors:
canonical debian rack-cors_project
CVE-2020-8891
5.9 MEDIUM

An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

Published: 2020-02-12
Products: 1
Vendors:
misp

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact ...

Published: 2020-06-04
Products: 1
Vendors:
indutny

An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appen...

Published: 2020-06-22
Products: 2
Vendors:
jsrsasign_project netapp

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnam...

Published: 2020-08-31
Products: 6
Vendors:
flask-cors_project opensuse debian

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

Published: 2020-10-01
Products: 1
Vendors:
envoyproxy
CVE-2020-17029
5.5 MEDIUM

Windows Canonical Display Driver Information Disclosure Vulnerability

Published: 2020-11-11
Products: 20
Vendors:
microsoft
CVE-2020-26241
6.5 MEDIUM

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where v...

Published: 2020-11-25
Products: 1
Vendors:
ethereum
CVE-2020-26265
5.3 MEDIUM

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where ...

Published: 2020-12-11
Products: 1
Vendors:
ethereum
CVE-2021-39137
6.5 MEDIUM

go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ethereum (Geth) could cause a chain split, where vulnerable versions refuse...

Published: 2021-08-24
Products: 1
Vendors:
ethereum

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside...

Published: 2021-11-04
Products: 2
Vendors:
jenkins

Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error ...

Published: 2021-12-13
Products: 6
Vendors:
linuxfoundation

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

Published: 2022-01-01
Products: 4
Vendors:
netapp golang debian

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonic...

Published: 2022-05-06
Products: 1
Vendors:
contao

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlie...

Published: 2022-07-05
Products: 4
Vendors:
fedoraproject xmlsoft lxml