Search CVE reports


Toggle filters

31 – 40 of 31984 results

Status is adjusted based on your filters.


CVE-2024-47537

Medium priority
Needs evaluation

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type...

2 affected packages

gst-plugins-good0.10, gst-plugins-good1.0

Package 18.04 LTS
gst-plugins-good0.10
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2024-45337

Medium priority
Needs evaluation

Applications and libraries which misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass.

3 affected packages

golang-go.crypto, lxd, snapd

Package 18.04 LTS
golang-go.crypto Needs evaluation
lxd Needs evaluation
snapd Needs evaluation
Show less packages

CVE-2024-4109

Medium priority
Needs evaluation

A flaw was found in Undertow. An HTTP request header value from a previous stream may be incorrectly reused for a request associated with a subsequent stream on the same HTTP/2 connection. This issue can potentially lead...

1 affected package

undertow

Package 18.04 LTS
undertow Needs evaluation
Show less packages

CVE-2024-11053

Low priority
Needs evaluation

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the...

1 affected package

curl

Package 18.04 LTS
curl Needs evaluation
Show less packages

CVE-2024-46657

Medium priority
Needs evaluation

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

1 affected package

mupdf

Package 18.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2024-54152

Medium priority
Needs evaluation

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the...

1 affected package

angular.js

Package 18.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2024-55601

Medium priority
Needs evaluation

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are...

1 affected package

hugo

Package 18.04 LTS
hugo Needs evaluation
Show less packages

CVE-2024-55566

Medium priority
Needs evaluation

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

1 affected package

colpack

Package 18.04 LTS
colpack Needs evaluation
Show less packages

CVE-2024-55564

Medium priority
Needs evaluation

The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

1 affected package

libposix-2008-perl

Package 18.04 LTS
libposix-2008-perl Needs evaluation
Show less packages

CVE-2024-46901

Medium priority
Needs evaluation

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users...

1 affected package

subversion

Package 18.04 LTS
subversion Needs evaluation
Show less packages