Search CVE reports
161 – 170 of 35777 results
Not in release
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by...
1 affected package
gitlab
| Package | 22.04 LTS |
|---|---|
| gitlab | Not in release |
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising...
1 affected package
logback
| Package | 22.04 LTS |
|---|---|
| logback | Needs evaluation |
Not in release
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial...
1 affected package
gitlab
| Package | 22.04 LTS |
|---|---|
| gitlab | Not in release |
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions...
2 affected packages
wheel, python-pip
| Package | 22.04 LTS |
|---|---|
| wheel | Needs evaluation |
| python-pip | Needs evaluation |
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
1 affected package
pytest
| Package | 22.04 LTS |
|---|---|
| pytest | Needs evaluation |
jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, and 4.0.4, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause...
1 affected package
node-diff
| Package | 22.04 LTS |
|---|---|
| node-diff | Needs evaluation |
Not in release
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which...
1 affected package
golang-github-theupdateframework-go-tuf
| Package | 22.04 LTS |
|---|---|
| golang-github-theupdateframework-go-tuf | Not in release |
Not in release
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF...
1 affected package
golang-github-theupdateframework-go-tuf
| Package | 22.04 LTS |
|---|---|
| golang-github-theupdateframework-go-tuf | Not in release |
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations...
1 affected package
opencryptoki
| Package | 22.04 LTS |
|---|---|
| opencryptoki | Needs evaluation |