Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

61 – 70 of 21510 results

Status is adjusted based on your filters.


CVE-2024-53426

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

1 affected packages

ntopng

Package 24.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2024-53425

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential...

1 affected packages

assimp

Package 24.04 LTS
assimp Needs evaluation
Show less packages

CVE-2024-30896

Medium priority
Needs evaluation

InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in...

1 affected packages

influxdb

Package 24.04 LTS
influxdb Needs evaluation
Show less packages

CVE-2024-11596

Medium priority
Needs evaluation

ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

1 affected packages

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2024-11595

Medium priority
Needs evaluation

FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

1 affected packages

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2024-48899

Medium priority

Not in release

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

1 affected packages

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2024-45691

Medium priority

Not in release

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only...

1 affected packages

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2024-45690

Medium priority

Not in release

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

1 affected packages

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2024-45689

Medium priority

Not in release

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

1 affected packages

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2024-52595

Medium priority
Needs evaluation

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as...

1 affected packages

lxml-html-clean

Package 24.04 LTS
lxml-html-clean Needs evaluation
Show less packages