Search CVE reports
461 – 470 of 33695 results
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple...
1 affected package
scitokens-cpp
| Package | 24.04 LTS |
|---|---|
| scitokens-cpp | Needs evaluation |
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes...
1 affected package
scitokens-cpp
| Package | 24.04 LTS |
|---|---|
| scitokens-cpp | Needs evaluation |
Not in release
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability...
1 affected package
pjproject
| Package | 24.04 LTS |
|---|---|
| pjproject | Not in release |
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric...
1 affected package
golang-github-go-git-go-git
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...
1 affected package
golang-github-go-git-go-git
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
Not in release
Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...
1 affected package
check-mk
| Package | 24.04 LTS |
|---|---|
| check-mk | Not in release |
Not in release
Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will...
1 affected package
check-mk
| Package | 24.04 LTS |
|---|---|
| check-mk | Not in release |
RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only...
1 affected package
rauc
| Package | 24.04 LTS |
|---|---|
| rauc | Needs evaluation |
An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap...
1 affected package
mupdf
| Package | 24.04 LTS |
|---|---|
| mupdf | Needs evaluation |
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of...
1 affected package
dnsdist
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |