Search CVE reports


Toggle filters

9521 – 9530 of 60314 results


CVE-2024-39894

Medium priority
Fixed

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry...

2 affected packages

openssh-ssh1, openssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh-ssh1 Not affected Not affected Not affected Not affected
openssh Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-4467

Medium priority

Some fixes available 4 of 9

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large...

1 affected package

qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2024-39316

Medium priority
Ignored

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-32498

Medium priority

Some fixes available 18 of 24

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references...

3 affected packages

cinder, glance, nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cinder Fixed Fixed Fixed Needs evaluation
glance Fixed Fixed Fixed Needs evaluation
nova Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-38519

Medium priority
Needs evaluation

`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in...

1 affected package

yt-dlp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
yt-dlp Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-38857

Medium priority
Needs evaluation

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-32230

Medium priority

Some fixes available 5 of 7

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-32229

Medium priority
Ignored

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release
Show less packages

CVE-2024-32228

Medium priority
Vulnerable

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Vulnerable Not affected Not affected Not affected
libav Not in release Not in release Not in release
Show less packages

CVE-2024-39249

Medium priority
Ignored

Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular...

1 affected package

node-async

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-async Not affected Not affected Not affected Not affected
Show less packages