Search CVE reports
1481 – 1490 of 37592 results
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into...
2 affected packages
request-tracker4, request-tracker5
| Package | 24.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | Needs evaluation |
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious...
2 affected packages
request-tracker4, request-tracker5
| Package | 24.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | Needs evaluation |
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is...
2 affected packages
request-tracker4, request-tracker5
| Package | 24.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as...
1 affected package
jupyterhub
| Package | 24.04 LTS |
|---|---|
| jupyterhub | Needs evaluation |
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...
1 affected package
ruby-devise
| Package | 24.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.
2 affected packages
golang-golang-x-sys, google-guest-agent
| Package | 24.04 LTS |
|---|---|
| golang-golang-x-sys | Needs evaluation |
| google-guest-agent | Needs evaluation |
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...
1 affected package
pcmanfm-qt
| Package | 24.04 LTS |
|---|---|
| pcmanfm-qt | Needs evaluation |
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...
7 affected packages
jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...
| Package | 24.04 LTS |
|---|---|
| jruby | Needs evaluation |
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Not in release |
| ruby3.2 | Needs evaluation |
| ruby3.3 | Not in release |