Search CVE reports


Toggle filters

181 – 190 of 25687 results

Status is adjusted based on your filters.


CVE-2024-11668

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls,...

1 affected package

gitlab

Package 22.04 LTS
gitlab Not in release
Show less packages

CVE-2024-11407

Medium priority
Needs evaluation

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent...

1 affected package

grpc

Package 22.04 LTS
grpc Needs evaluation
Show less packages

CVE-2024-36463

Medium priority
Needs evaluation

The implementation of atob in “Zabbix JS” allows to create a string with arbitrary content and use it to access internal properties of objects.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-22117

Medium priority
Needs evaluation

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a...

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2023-2142

Medium priority

Not in release

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was...

1 affected package

node-nunjucks

Package 22.04 LTS
node-nunjucks Not in release
Show less packages

CVE-2024-53976

Low priority
Vulnerable

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 22.04 LTS
firefox Not affected
mozjs102 Ignored
mozjs115 Not in release
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
thunderbird Vulnerable
Show all 9 packages Show less packages

CVE-2024-53620

Medium priority
Needs evaluation

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2024-53619

Medium priority
Needs evaluation

An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2024-52337

Medium priority
Needs evaluation

A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be inserted into the log. Instead of the...

1 affected package

tuned

Package 22.04 LTS
tuned Needs evaluation
Show less packages

CVE-2024-52336

Medium priority
Needs evaluation

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute...

1 affected package

tuned

Package 22.04 LTS
tuned Needs evaluation
Show less packages