Search CVE reports
1431 – 1440 of 28306 results
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects...
2 affected packages
eglibc, glibc
Package | 24.04 LTS |
---|---|
eglibc | Not in release |
glibc | Fixed |
Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the...
1 affected package
redis
Package | 24.04 LTS |
---|---|
redis | Needs evaluation |
Not in release
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Not in release
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when...
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
1 affected package
apache2
Package | 24.04 LTS |
---|---|
apache2 | Not affected |
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000...
1 affected package
xdebug
Package | 24.04 LTS |
---|---|
xdebug | Needs evaluation |
Not in release
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
1 affected package
maas
Package | 24.04 LTS |
---|---|
maas | Not in release |
Not in release
ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of...
1 affected package
viewvc
Package | 24.04 LTS |
---|---|
viewvc | Not in release |
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2...
1 affected package
suricata
Package | 24.04 LTS |
---|---|
suricata | Needs evaluation |
Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS |
---|---|
firefox | Not affected |
thunderbird | Not affected |
mozjs38 | Not in release |
mozjs52 | Not in release |
mozjs68 | Not in release |
mozjs78 | Not in release |
mozjs91 | Not in release |
mozjs102 | Ignored |
mozjs115 | Ignored |