Search CVE reports


Toggle filters

71 – 80 of 31984 results

Status is adjusted based on your filters.


CVE-2024-54661

Low priority
Needs evaluation

readline.sh in socat through 1.8.0.1 relies on the /tmp/$USER/stderr2 file.

1 affected package

socat

Package 18.04 LTS
socat Needs evaluation
Show less packages

CVE-2024-53867

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages,...

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-53863

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon...

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-52815

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts...

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-52805

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which...

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-37303

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media...

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-37302

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media....

1 affected package

matrix-synapse

Package 18.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2024-48916

Medium priority
Not affected

Authentication bypass in CEPH RadosGW

1 affected package

ceph

Package 18.04 LTS
ceph Not affected
Show less packages

CVE-2024-53988

Medium priority
Needs evaluation

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...

1 affected package

ruby-rails-html-sanitizer

Package 18.04 LTS
ruby-rails-html-sanitizer Needs evaluation
Show less packages

CVE-2024-53987

Medium priority
Needs evaluation

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...

1 affected package

ruby-rails-html-sanitizer

Package 18.04 LTS
ruby-rails-html-sanitizer Needs evaluation
Show less packages