Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2022-46165

Medium priority
Needs evaluation

Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance with shared folders could sync malicious files which contain arbitrary HTML and JavaScript in the name. If...

1 affected package

syncthing

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31129

Medium priority

Some fixes available 4 of 118

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...

11 affected packages

node-moment, wordpress, mediawiki, syncthing, omnidb...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-moment Not affected Not affected Fixed Fixed Fixed
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
omnidb Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
postfixadmin Vulnerable Vulnerable Fixed Not affected Not affected
sabnzbdplus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gnucash Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
odoo Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
ruby-momentjs-rails Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
Show all 11 packages Show less packages

CVE-2021-21404

Medium priority
Vulnerable

Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message with a negative length field....

1 affected package

syncthing

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
syncthing Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2017-1000420

Medium priority
Ignored

Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite

1 affected package

syncthing

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
syncthing — — — — Not affected
Show less packages