Search CVE reports
1 – 10 of 21 results
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided...
1 affected package
pcs
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | Vulnerable | Vulnerable | Vulnerable | Not affected | Not affected |
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted...
1 affected package
pcsx2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcsx2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a...
1 affected package
pcsx2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcsx2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 2 of 3
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication...
1 affected package
pcs
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | Not affected | Not affected | Fixed | Not affected | Not affected |
Some fixes available 2 of 3
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that...
1 affected package
pcs
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | Not affected | Not affected | Fixed | Fixed | Not affected |
Some fixes available 5 of 6
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This...
3 affected packages
pcs, drupal7, jquery
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | Not affected | Not affected | Not affected | Not affected | Not affected |
| drupal7 | — | Not in release | Not in release | Not in release | Not in release |
| jquery | — | Not in release | Not in release | Fixed | Fixed |
Some fixes available 4 of 5
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....
3 affected packages
pcs, drupal7, jquery
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | Not affected | Not affected | Not affected | Not affected | Not affected |
| drupal7 | — | Not in release | Not in release | Not in release | Not in release |
| jquery | — | Not in release | Not in release | Fixed | Fixed |
Some fixes available 3 of 31
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...
6 affected packages
node-jquery, drupal7, mediawiki, otrs2, pcs, jquery
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| node-jquery | Not affected | Not affected | Not affected | Not affected | Vulnerable |
| drupal7 | Not in release | Not in release | Not in release | Not in release | Not in release |
| mediawiki | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| otrs2 | Not in release | Not in release | Needs evaluation | Not affected | Needs evaluation |
| pcs | Not affected | Not affected | Not affected | Not affected | Not affected |
| jquery | Not in release | Not in release | Not in release | Not affected | Fixed |
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query....
1 affected package
pcs
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | — | — | — | — | Not affected |
Some fixes available 1 of 3
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive...
1 affected package
pcs
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcs | — | Not affected | Not affected | Not affected | Not affected |