Search CVE reports


Toggle filters

9541 – 9550 of 60314 results


CVE-2024-38999

Medium priority
Needs evaluation

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting...

1 affected package

requirejs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
requirejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-38998

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

requirejs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
requirejs Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-6387

High priority
Fixed

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Not affected Not affected
openssh-ssh1 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-1724

Medium priority

Some fixes available 6 of 7

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An...

1 affected package

snapd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
snapd Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-34703

Medium priority

Some fixes available 3 of 5

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an attacker could present an...

1 affected package

botan

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan Fixed Fixed Vulnerable Not affected
Show less packages

CVE-2019-25211

Medium priority
Needs evaluation

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should...

1 affected package

golang-github-gin-contrib-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gin-contrib-cors Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-37371

Medium priority

Some fixes available 6 of 7

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

1 affected package

krb5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
krb5 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-37370

Medium priority

Some fixes available 6 of 7

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.

1 affected package

krb5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
krb5 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-38528

Medium priority
Needs evaluation

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE connections. This allows an unauthenticated remote attacker to crash ntpd-rs when an...

1 affected package

rust-ntpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-ntpd Needs evaluation Not in release Not in release
Show less packages

CVE-2024-27629

Medium priority
Needs evaluation

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

1 affected package

dcm2niix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcm2niix Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages