Search CVE reports


Toggle filters

41 – 50 of 465 results


CVE-2024-45239

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45238

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45237

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45236

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45235

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45234

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-43791

Medium priority
Needs evaluation

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This...

1 affected package

ruby-request-store

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-request-store Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-43411

Negligible priority

Some fixes available 3 of 23

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over...

4 affected packages

ckeditor3, ldap-account-manager, request-tracker4, ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-43407

Medium priority
Needs evaluation

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in...

5 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4, geshi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Not affected Not affected Not affected Not affected
ldap-account-manager Not affected Not affected Not affected Not affected
request-tracker4 Not affected Not affected Not affected Not affected
geshi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-35198

Medium priority
Ignored

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Not affected Not in release
Show less packages