Search CVE reports
71 – 80 of 31984 results
CVE-2024-54661
Low priorityreadline.sh in socat through 1.8.0.1 relies on the /tmp/$USER/stderr2 file.
1 affected package
socat
Package | 18.04 LTS |
---|---|
socat | Needs evaluation |
CVE-2024-53867
Medium prioritySynapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages,...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-53863
Medium prioritySynapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-52815
Medium prioritySynapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-52805
Medium prioritySynapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-37303
Medium prioritySynapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media...
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-37302
Medium prioritySynapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media....
1 affected package
matrix-synapse
Package | 18.04 LTS |
---|---|
matrix-synapse | Needs evaluation |
CVE-2024-48916
Medium priorityAuthentication bypass in CEPH RadosGW
1 affected package
ceph
Package | 18.04 LTS |
---|---|
ceph | Not affected |
CVE-2024-53988
Medium priorityrails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...
1 affected package
ruby-rails-html-sanitizer
Package | 18.04 LTS |
---|---|
ruby-rails-html-sanitizer | Needs evaluation |
CVE-2024-53987
Medium priorityrails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...
1 affected package
ruby-rails-html-sanitizer
Package | 18.04 LTS |
---|---|
ruby-rails-html-sanitizer | Needs evaluation |