Search CVE reports
41 – 50 of 47927 results
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS |
|---|---|
| expat | Needs evaluation |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Not in release |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Not in release |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | Not in release |
| cableswig | Not in release |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | Not in release |
| smart | Not in release |
| firefox | Not affected |
| thunderbird | Not affected |
| libxmltok | Needs evaluation |
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name)...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 24.04 LTS |
|---|---|
| kamailio | Needs evaluation |
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...
2 affected packages
varnish, vinyl-cache
| Package | 24.04 LTS |
|---|---|
| varnish | Needs evaluation |
| vinyl-cache | Not in release |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...
1 affected package
blazar
| Package | 24.04 LTS |
|---|---|
| blazar | Not in release |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...
1 affected package
blazar
| Package | 24.04 LTS |
|---|---|
| blazar | Not in release |
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in...
1 affected package
node-deepmerge
| Package | 24.04 LTS |
|---|---|
| node-deepmerge | Needs evaluation |