Search CVE reports
141 – 150 of 49076 results
Not in release
GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of...
1 affected package
glpi
| Package | 24.04 LTS |
|---|---|
| glpi | Not in release |
[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]
5 affected packages
libpng, libpng1.6, firefox, thunderbird, chromium-browser
| Package | 24.04 LTS |
|---|---|
| libpng | Not in release |
| libpng1.6 | Needs evaluation |
| firefox | Not affected |
| thunderbird | Not affected |
| chromium-browser | Not affected |
Not in release
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the...
1 affected package
glpi
| Package | 24.04 LTS |
|---|---|
| glpi | Not in release |
QUIC Unvalidated Amplification Credit may be Over Accounted
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Some fixes available 1 of 2
Excessive Memory Allocation in Relative CRLDP Processing
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Not in release |
In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028,...
1 affected package
node-shell-quote
| Package | 24.04 LTS |
|---|---|
| node-shell-quote | Needs evaluation |
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...
1 affected package
node-pbkdf2
| Package | 24.04 LTS |
|---|---|
| node-pbkdf2 | Needs evaluation |
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument...
1 affected package
wsl-pro-service
| Package | 24.04 LTS |
|---|---|
| wsl-pro-service | Vulnerable |
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are...
1 affected package
zoneminder
| Package | 24.04 LTS |
|---|---|
| zoneminder | Needs evaluation |