Search CVE reports
31 – 40 of 31984 results
CVE-2024-47537
Medium priorityGStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 18.04 LTS |
---|---|
gst-plugins-good0.10 | — |
gst-plugins-good1.0 | Needs evaluation |
CVE-2024-45337
Medium priorityApplications and libraries which misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass.
3 affected packages
golang-go.crypto, lxd, snapd
Package | 18.04 LTS |
---|---|
golang-go.crypto | Needs evaluation |
lxd | Needs evaluation |
snapd | Needs evaluation |
CVE-2024-4109
Medium priorityA flaw was found in Undertow. An HTTP request header value from a previous stream may be incorrectly reused for a request associated with a subsequent stream on the same HTTP/2 connection. This issue can potentially lead...
1 affected package
undertow
Package | 18.04 LTS |
---|---|
undertow | Needs evaluation |
CVE-2024-11053
Low priorityWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the...
1 affected package
curl
Package | 18.04 LTS |
---|---|
curl | Needs evaluation |
CVE-2024-46657
Medium priorityArtifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
1 affected package
mupdf
Package | 18.04 LTS |
---|---|
mupdf | Needs evaluation |
CVE-2024-54152
Medium priorityAngular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the...
1 affected package
angular.js
Package | 18.04 LTS |
---|---|
angular.js | Needs evaluation |
CVE-2024-55601
Medium priorityHugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are...
1 affected package
hugo
Package | 18.04 LTS |
---|---|
hugo | Needs evaluation |
CVE-2024-55566
Medium priorityColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.
1 affected package
colpack
Package | 18.04 LTS |
---|---|
colpack | Needs evaluation |
CVE-2024-55564
Medium priorityThe POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
1 affected package
libposix-2008-perl
Package | 18.04 LTS |
---|---|
libposix-2008-perl | Needs evaluation |
CVE-2024-46901
Medium priorityInsufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users...
1 affected package
subversion
Package | 18.04 LTS |
---|---|
subversion | Needs evaluation |