In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
Category Archives: Advisories
CVE-2020-23561
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
CVE-2020-23562
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.
CVE-2020-23563
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
mariadb-10.3-3520220716094844.f27b74a8
FEDORA-MODULAR-2022-0cd0202272
Packages in this update:
mariadb-10.3-3520220716094844.f27b74a8
Update description:
MariaDB 10.3.35 & Galera 25.3.35
Important notice:
This is the last planned update for this module stream in Fedora.
Fedora 35 will be the last Fedora release in which this module stream will be available.
mariadb-10.4-3520220717092835.f27b74a8
FEDORA-MODULAR-2022-c58e1ae21e
Packages in this update:
mariadb-10.4-3520220717092835.f27b74a8
Update description:
MariaDB 10.4.25 & Galera 26.4.11
Important notice:
This is the last planned update for this module stream in Fedora.
Fedora 35 will be the last Fedora release in which this module stream will be available.
CVE-2015-10003
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20132
A vulnerability was found in Itech Multi Vendor Script 6.49 and classified as critical. This issue affects some unknown processing of the file /multi-vendor-shopping-script/product-list.php. The manipulation of the argument pl leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20133
A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.
CVE-2017-20134
A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument sk leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.