Search CVE reports


Toggle filters

9461 – 9470 of 60314 results


CVE-2024-38095

Medium priority

Some fixes available 5 of 7

.NET and Visual Studio Denial of Service Vulnerability

3 affected packages

dotnet6, dotnet7, dotnet8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dotnet6 Not in release Fixed Not in release Not in release
dotnet7 Not in release Ignored Not in release Not in release
dotnet8 Fixed Fixed Not in release Not in release
Show less packages

CVE-2024-38081

Medium priority
Ignored

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

3 affected packages

dotnet6, dotnet7, dotnet8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dotnet6 Not in release Not affected Not in release Not in release
dotnet7 Not in release Ignored Not in release Not in release
dotnet8 Not affected Not affected Not in release Not in release
Show less packages

CVE-2024-35264

Medium priority

Some fixes available 3 of 5

.NET and Visual Studio Remote Code Execution Vulnerability

3 affected packages

dotnet6, dotnet7, dotnet8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dotnet6 Not in release Not affected Not in release Not in release
dotnet7 Not in release Ignored Not in release Not in release
dotnet8 Fixed Fixed Not in release Not in release
Show less packages

CVE-2024-30105

Medium priority

Some fixes available 3 of 5

.NET and Visual Studio Denial of Service Vulnerability

3 affected packages

dotnet6, dotnet7, dotnet8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dotnet6 Not in release Not affected Not in release Not in release
dotnet7 Not in release Ignored Not in release Not in release
dotnet8 Fixed Fixed Not in release Not in release
Show less packages

CVE-2024-3653

Medium priority
Needs evaluation

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which...

1 affected package

undertow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-5971

Medium priority
Needs evaluation

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected...

1 affected package

undertow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-38372

Medium priority
Needs evaluation

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been...

1 affected package

node-undici

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-undici Needs evaluation Not in release Not in release
Show less packages

CVE-2024-1305

Medium priority
Ignored

tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code...

1 affected package

openvpn

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-39312

Medium priority

Some fixes available 3 of 6

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509...

1 affected package

botan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan Fixed Fixed Vulnerable Ignored
Show less packages

CVE-2024-34702

Medium priority

Some fixes available 3 of 6

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509...

1 affected package

botan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan Fixed Fixed Ignored Ignored
Show less packages