Search CVE reports
61 – 70 of 28952 results
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap...
1 affected package
libssh2
| Package | 26.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation...
1 affected package
coturn
| Package | 26.04 LTS |
|---|---|
| coturn | Needs evaluation |
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger...
1 affected package
nilfs-tools
| Package | 26.04 LTS |
|---|---|
| nilfs-tools | Needs evaluation |
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.
1 affected package
nodejs
| Package | 26.04 LTS |
|---|---|
| nodejs | Needs evaluation |
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations....
1 affected package
nodejs
| Package | 26.04 LTS |
|---|---|
| nodejs | Needs evaluation |
Not in release
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a...
1 affected package
eclipse
| Package | 26.04 LTS |
|---|---|
| eclipse | Not in release |
Not in release
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository...
1 affected package
eclipse
| Package | 26.04 LTS |
|---|---|
| eclipse | Not in release |
Not in release
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious...
1 affected package
eclipse
| Package | 26.04 LTS |
|---|---|
| eclipse | Not in release |
Not in release
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious...
1 affected package
eclipse
| Package | 26.04 LTS |
|---|---|
| eclipse | Not in release |
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |