Search CVE reports


Toggle filters

7121 – 7130 of 60505 results


CVE-2024-21853

Medium priority

Some fixes available 6 of 7

Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.

1 affected package

intel-microcode

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
intel-microcode Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-21820

Medium priority

Some fixes available 6 of 7

Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

1 affected package

intel-microcode

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
intel-microcode Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-21808

Medium priority
Needs evaluation

Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

2 affected packages

intel-mediasdk, onevpl-intel-gpu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
intel-mediasdk Needs evaluation Needs evaluation Needs evaluation
onevpl-intel-gpu Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-21783

Medium priority
Needs evaluation

Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

2 affected packages

intel-mediasdk, onevpl-intel-gpu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
intel-mediasdk Needs evaluation Needs evaluation Needs evaluation
onevpl-intel-gpu Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-9476

Medium priority
Needs evaluation

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2024-51996

Medium priority

Some fixes available 1 of 4

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Fixed Needs evaluation Not affected Not affected
Show less packages

CVE-2024-49504

Medium priority
Needs evaluation

grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-48900

Medium priority
Not affected

A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not affected
Show less packages

CVE-2024-11159

Medium priority
Not affected

Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Not affected Not in release
Show less packages

CVE-2024-11168

Medium priority
Fixed

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 Not in release Fixed Fixed Fixed
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Fixed
python3.7 Not in release Not in release Not in release Fixed
python3.8 Not in release Not in release Fixed Fixed
python3.9 Not in release Not in release Fixed
python3.10 Not in release Fixed Not in release
python3.11 Not in release Fixed Not in release
python3.12 Not affected Not in release Not in release
python3.13 Not in release Not in release Not in release
Show all 11 packages Show less packages