Search CVE reports
1 – 10 of 29276 results
The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically...
1 affected package
request-tracker5
| Package | 24.04 LTS |
|---|---|
| request-tracker5 | Needs evaluation |
Not in release
[Unknown description]
1 affected package
gitlab
| Package | 24.04 LTS |
|---|---|
| gitlab | Not in release |
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in...
1 affected package
lz4
| Package | 24.04 LTS |
|---|---|
| lz4 | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using...
1 affected package
pypdf
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has...
1 affected package
pypdf
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can expand into tens or hundreds of...
1 affected package
python-authlib
| Package | 24.04 LTS |
|---|---|
| python-authlib | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon...
1 affected package
virtualbox
| Package | 24.04 LTS |
|---|---|
| virtualbox | Needs evaluation |
aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the...
1 affected package
aiomysql
| Package | 24.04 LTS |
|---|---|
| aiomysql | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon...
1 affected package
virtualbox
| Package | 24.04 LTS |
|---|---|
| virtualbox | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon...
1 affected package
virtualbox
| Package | 24.04 LTS |
|---|---|
| virtualbox | Needs evaluation |