Search CVE reports
61 – 70 of 26149 results
A vulnerability was found in CodeMirror up to 5.17.0 and classified as problematic. Affected by this issue is some unknown functionality of the file mode/markdown/markdown.js of the component Markdown Mode. The manipulation leads...
1 affected package
codemirror-js
Package | 24.04 LTS |
---|---|
codemirror-js | Needs evaluation |
A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based...
1 affected package
ruby-nokogiri
Package | 24.04 LTS |
---|---|
ruby-nokogiri | Vulnerable |
A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer...
1 affected package
poco
Package | 24.04 LTS |
---|---|
poco | Needs evaluation |
pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name resolutions asynchronously. Prior to version 4.9.0, pycares is vulnerable to a use-after-free...
1 affected package
pycares
Package | 24.04 LTS |
---|---|
pycares | Needs evaluation |
Not in release
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Not in release
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Not in release
An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Not in release
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the...
1 affected package
hoteldruid
Package | 24.04 LTS |
---|---|
hoteldruid | Needs evaluation |
Not in release
An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |