Search CVE reports
91 – 100 of 42041 results
security update
1 affected package
udisks2
| Package | 24.04 LTS |
|---|---|
| udisks2 | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all()...
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses...
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
Not in release
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri...
1 affected package
open62541
| Package | 24.04 LTS |
|---|---|
| open62541 | Not in release |