Search CVE reports


Toggle filters

7091 – 7100 of 60505 results


CVE-2024-47759

Medium priority
Needs evaluation

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.

1 affected package

glpi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release
Show less packages

CVE-2024-41678

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

1 affected package

glpi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release
Show less packages

CVE-2024-40638

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

1 affected package

glpi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release
Show less packages

CVE-2021-1494

Medium priority
Needs evaluation

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect...

1 affected package

snort

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
snort Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-50986

Medium priority
Needs evaluation

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

1 affected package

clementine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clementine Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-4679

Medium priority
Needs evaluation

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause...

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-3991

Medium priority
Needs evaluation

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access,...

1 affected package

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dolibarr Not in release Not in release Not in release
Show less packages

CVE-2021-3902

Medium priority
Not affected

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The...

1 affected package

php-dompdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2024-52308

High priority

Some fixes available 2 of 3

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the...

1 affected package

gh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gh Fixed Not affected Not in release
Show less packages

CVE-2024-10397

Medium priority
Needs evaluation

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

1 affected package

openafs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openafs Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages