Search CVE reports
81 – 90 of 49529 results
security update
6 affected packages
chromium-browser, webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 24.04 LTS |
|---|---|
| chromium-browser | Not affected |
| webkitgtk | Not in release |
| webkit2gtk | Needs evaluation |
| qtwebkit-source | Not in release |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Not in release |
(The gist RubyGem before 6.1.0 contains an improper certificate validat ...)
1 affected package
gist
| Package | 24.04 LTS |
|---|---|
| gist | Needs evaluation |
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the...
1 affected package
imagemagick
| Package | 24.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
Not in release
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The...
1 affected package
dogtag-pki
| Package | 24.04 LTS |
|---|---|
| dogtag-pki | Not in release |
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation,...
1 affected package
python-multidict
| Package | 24.04 LTS |
|---|---|
| python-multidict | Needs evaluation |
Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an...
1 affected package
rust-wasmtime
| Package | 24.04 LTS |
|---|---|
| rust-wasmtime | Needs evaluation |
fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents...
1 affected package
fsspec
| Package | 24.04 LTS |
|---|---|
| fsspec | Needs evaluation |
Not in release
uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including...
2 affected packages
uv, uv-full
| Package | 24.04 LTS |
|---|---|
| uv | Not in release |
| uv-full | Not in release |
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
1 affected package
ejabberd
| Package | 24.04 LTS |
|---|---|
| ejabberd | Needs evaluation |
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender...
1 affected package
logback
| Package | 24.04 LTS |
|---|---|
| logback | Needs evaluation |