Search CVE reports
71 – 80 of 33052 results
ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented...
1 affected package
freeipmi
| Package | 24.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
[Unknown description]
2 affected packages
squid, squid3
| Package | 24.04 LTS |
|---|---|
| squid | Needs evaluation |
| squid3 | Not in release |
[Unknown description]
2 affected packages
squid, squid3
| Package | 24.04 LTS |
|---|---|
| squid | Needs evaluation |
| squid3 | Not in release |
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the...
1 affected package
php-league-commonmark
| Package | 24.04 LTS |
|---|---|
| php-league-commonmark | Needs evaluation |
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version 3.0.0 and prior to version 3.3.1, Dasel's YAML reader allows an attacker who can supply YAML for processing to...
1 affected package
dasel
| Package | 24.04 LTS |
|---|---|
| dasel | Needs evaluation |
Not in release
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension. An attacker with access to...
1 affected package
mod-gnutls
| Package | 24.04 LTS |
|---|---|
| mod-gnutls | Not in release |
Not in release
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t...
1 affected package
mod-gnutls
| Package | 24.04 LTS |
|---|---|
| mod-gnutls | Not in release |
Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public...
1 affected package
freeciv
| Package | 24.04 LTS |
|---|---|
| freeciv | Needs evaluation |
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via...
1 affected package
nats-server
| Package | 24.04 LTS |
|---|---|
| nats-server | Needs evaluation |
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception...
1 affected package
rails
| Package | 24.04 LTS |
|---|---|
| rails | Needs evaluation |