Search CVE reports


Toggle filters

41 – 50 of 848 results


CVE-2024-44337

Medium priority
Needs evaluation

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with...

1 affected package

golang-github-gomarkdown-markdown

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gomarkdown-markdown Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2024-21535

Medium priority
Needs evaluation

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe...

1 affected package

node-markdown-to-jsx

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-markdown-to-jsx Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2024-9781

Medium priority
Vulnerable

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-9780

Medium priority
Vulnerable

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Not affected
Show less packages

CVE-2024-8645

Low priority
Vulnerable

SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-8418

Medium priority
Ignored

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the...

1 affected package

aardvark-dns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aardvark-dns Not affected Not in release Not in release
Show less packages

CVE-2024-8250

Medium priority
Vulnerable

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-4855

Medium priority
Vulnerable

Use after free issue in editcap could cause denial of service via crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-4854

Medium priority
Vulnerable

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-4853

Medium priority
Vulnerable

Memory handling issue in editcap could cause denial of service via crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages