Search CVE reports


Toggle filters

171 – 180 of 846 results


CVE-2020-11888

Medium priority
Needs evaluation

python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.

1 affected package

python-markdown2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-markdown2 Not affected Not affected Needs evaluation Not in release
Show less packages

CVE-2020-11647

Medium priority
Vulnerable

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9431

Low priority
Vulnerable

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9430

Low priority
Vulnerable

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9429

Low priority
Not affected

In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected
Show less packages

CVE-2020-9428

Low priority
Vulnerable

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-7045

Low priority
Vulnerable

In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-7044

Medium priority
Not affected

In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected
Show less packages

CVE-2014-3743

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript...

1 affected package

node-marked

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-marked Not affected
Show less packages

CVE-2014-1850

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3743. Reason: This candidate is a duplicate of CVE-2014-3743. Notes: All CVE users should reference CVE-2014-3743 instead of this candidate. All references...

1 affected package

node-marked

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-marked
Show less packages