Search CVE reports


Toggle filters

361 – 370 of 1370 results


CVE-2024-40630

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature...

1 affected package

openimageio

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openimageio Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-5470

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

2 affected packages

gitlab, gitlab-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release —
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
Show less packages

CVE-2024-5257

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the...

2 affected packages

gitlab, gitlab-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release —
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
Show less packages

CVE-2024-2880

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role...

2 affected packages

gitlab, gitlab-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release —
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
Show less packages

CVE-2024-6501

Low priority
Vulnerable

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager...

1 affected package

network-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager Not affected Vulnerable Not affected Not affected Not affected
Show less packages

CVE-0000-0001

Medium priority

Some fixes available 1 of 2

TEST CVE 1

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick — Not affected Fixed Vulnerable Not affected
Show less packages

CVE-2024-24792

Medium priority
Needs evaluation

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

1 affected package

golang-golang-x-image

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-image Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-6388

Medium priority

Some fixes available 5 of 6

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

1 affected package

ubuntu-advantage-desktop-daemon

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ubuntu-advantage-desktop-daemon — Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-39331

Medium priority

Some fixes available 10 of 32

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

6 affected packages

xemacs21, xemacs21-packages, emacs, emacs24, emacs25, org-mode

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xemacs21 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xemacs21-packages Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emacs Not affected Fixed Fixed Fixed —
emacs24 Not in release Not in release Not in release Not in release —
emacs25 Not in release Not in release Not in release Not in release Fixed
org-mode Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-3661

High priority
Ignored

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An...

29 affected packages

connman, gadmin-openvpn-client, gadmin-openvpn-server, golang-github-apparentlymart-go-openvpn-mgmt, kvpnc...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
connman — Ignored Ignored Ignored Ignored
gadmin-openvpn-client — Not in release Not in release Ignored Ignored
gadmin-openvpn-server — Not in release Not in release Ignored Ignored
golang-github-apparentlymart-go-openvpn-mgmt — Ignored Ignored Ignored —
kvpnc — Not in release Not in release Not in release Ignored
libreswan — Ignored Ignored Ignored Ignored
mozillavpn — Not in release Ignored Not in release —
n2n — Ignored Ignored Ignored Ignored
network-manager-fortisslvpn — Ignored Ignored Ignored Ignored
network-manager-iodine — Ignored Ignored Ignored Ignored
network-manager-l2tp — Ignored Ignored Ignored Ignored
network-manager-openconnect — Ignored Ignored Ignored Ignored
network-manager-openvpn — Ignored Ignored Ignored Ignored
network-manager-pptp — Ignored Ignored Ignored Ignored
network-manager-sstp — Ignored Ignored Not in release —
network-manager-strongswan — Ignored Ignored Ignored Ignored
network-manager-vpnc — Ignored Ignored Ignored Ignored
openconnect — Ignored Ignored Ignored Ignored
openfortivpn — Ignored Ignored Ignored Ignored
openvpn — Ignored Ignored Ignored Ignored
pptp-linux — Ignored Ignored Ignored Ignored
pptpd — Not in release Ignored Ignored Ignored
quicktun — Ignored Ignored Ignored Ignored
riseup-vpn — Ignored Not in release Not in release —
softether-vpn — Ignored Ignored Not in release —
sshuttle — Ignored Ignored Ignored Ignored
tinc — Ignored Ignored Ignored Ignored
vpnc — Ignored Ignored Ignored Ignored
wireguard — Ignored Ignored Ignored Ignored
Show all 29 packages Show less packages