Search CVE reports


Toggle filters

31 – 40 of 465 results


CVE-2024-52804

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-1932

Medium priority
Needs evaluation

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character....

1 affected package

libhibernate-validator-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-51774

Medium priority
Needs evaluation

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

1 affected package

qbittorrent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qbittorrent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-48063

Medium priority
Needs evaluation

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2024-21272

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network...

1 affected package

mysql-connector-python

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-python Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-21262

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network...

1 affected package

mysql-connector-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-9676

Medium priority
Needs evaluation

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running...

2 affected packages

golang-github-containers-buildah, golang-github-containers-storage

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Not in release
golang-github-containers-storage Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37154

Medium priority
Needs evaluation

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

1 affected package

monitoring-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monitoring-plugins Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45613

Medium priority
Needs evaluation

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered...

4 affected packages

ckeditor3, ldap-account-manager, request-tracker4, ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-8796

Medium priority

Some fixes available 2 of 3

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to...

1 affected package

ruby-devise-two-factor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-devise-two-factor Not affected Fixed Fixed
Show less packages