Search CVE reports
631 – 640 of 47985 results
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's...
1 affected package
cyrus-imapd
| Package | 20.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue...
1 affected package
activemq
| Package | 20.04 LTS |
|---|---|
| activemq | Needs evaluation |
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
1 affected package
opam
| Package | 20.04 LTS |
|---|---|
| opam | Needs evaluation |
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm...
1 affected package
cjose
| Package | 20.04 LTS |
|---|---|
| cjose | Needs evaluation |
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`,...
1 affected package
cjose
| Package | 20.04 LTS |
|---|---|
| cjose | Needs evaluation |
(A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)
1 affected package
glib2.0
| Package | 20.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
(commonmark versions from 1.5.0 before 2.8.4 contain a denial of servic ...)
1 affected package
php-league-commonmark
| Package | 20.04 LTS |
|---|---|
| php-league-commonmark | Needs evaluation |