Search CVE reports
31 – 40 of 25562 results
Not in release
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
1 affected package
tcpreplay
Package | 24.04 LTS |
---|---|
tcpreplay | Needs evaluation |
yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.
1 affected package
yasm
Package | 24.04 LTS |
---|---|
yasm | Needs evaluation |
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an...
1 affected package
libio-compress-brotli-perl
Package | 24.04 LTS |
---|---|
libio-compress-brotli-perl | Needs evaluation |
Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when...
1 affected package
redis
Package | 24.04 LTS |
---|---|
redis | Needs evaluation |
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
11 affected packages
chromium-browser, firefox, libvpx, mozjs102, mozjs115...
Package | 24.04 LTS |
---|---|
chromium-browser | Not affected |
firefox | Not affected |
libvpx | Vulnerable |
mozjs102 | Ignored |
mozjs115 | Ignored |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Not in release |
mozjs91 | Not in release |
thunderbird | Not affected |
Race condition can result in confidential information leakage
1 affected package
apport
Package | 24.04 LTS |
---|---|
apport | Fixed |
[Thread creation while a directory handle is open does a fchdir, affecting other threads (race condition)]
1 affected package
perl
Package | 24.04 LTS |
---|---|
perl | Needs evaluation |
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
1 affected package
request-tracker5
Package | 24.04 LTS |
---|---|
request-tracker5 | Needs evaluation |
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
1 affected package
request-tracker5
Package | 24.04 LTS |
---|---|
request-tracker5 | Needs evaluation |