Search CVE reports


Toggle filters

141 – 150 of 25687 results

Status is adjusted based on your filters.


CVE-2024-35367

Medium priority
Needs evaluation

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2024-35366

Medium priority
Needs evaluation

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2024-53861

Medium priority
Not affected

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim...

1 affected package

pyjwt

Package 22.04 LTS
pyjwt Not affected
Show less packages

CVE-2024-36616

Medium priority
Needs evaluation

An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2024-36615

Medium priority
Needs evaluation

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2024-36611

Medium priority
Needs evaluation

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead...

1 affected package

symfony

Package 22.04 LTS
symfony Needs evaluation
Show less packages

CVE-2024-36623

Medium priority
Needs evaluation

moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

2 affected packages

docker.io, docker.io-app

Package 22.04 LTS
docker.io Needs evaluation
docker.io-app Needs evaluation
Show less packages

CVE-2024-36621

Medium priority
Needs evaluation

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

2 affected packages

docker.io, docker.io-app

Package 22.04 LTS
docker.io Needs evaluation
docker.io-app Needs evaluation
Show less packages

CVE-2024-47094

Medium priority

Not in release

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages

CVE-2024-48651

Medium priority
Vulnerable

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

1 affected package

proftpd-dfsg

Package 22.04 LTS
proftpd-dfsg Vulnerable
Show less packages