Search CVE reports


Toggle filters

9411 – 9420 of 60314 results


CVE-2024-37151

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure,...

1 affected package

suricata

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
suricata Needs evaluation Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2024-6385

Medium priority
Not affected

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2024-5470

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-5257

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-2880

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2016-15039

Medium priority
Needs evaluation

A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. The...

1 affected package

phpldapadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpldapadmin Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2024-6655

Medium priority

Some fixes available 10 of 16

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

2 affected packages

gtk+2.0, gtk+3.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gtk+2.0 Fixed Fixed Fixed Needs evaluation
gtk+3.0 Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-37149

Medium priority
Needs evaluation

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the...

1 affected package

glpi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release
Show less packages

CVE-2024-37148

Medium priority
Needs evaluation

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX...

1 affected package

glpi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release
Show less packages

CVE-2024-3325

Low priority
Needs evaluation

Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

1 affected package

jasperreports

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jasperreports Not in release Not in release Not in release Needs evaluation
Show less packages