Search CVE reports
101 – 110 of 47600 results
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline...
1 affected package
gitlab
| Package | 16.04 LTS |
|---|---|
| gitlab | Ignored |
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must...
1 affected package
grafana
| Package | 16.04 LTS |
|---|---|
| grafana | Needs evaluation |
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting...
1 affected package
udisks2
| Package | 16.04 LTS |
|---|---|
| udisks2 | Not affected |
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the...
1 affected package
udisks2
| Package | 16.04 LTS |
|---|---|
| udisks2 | Not affected |
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
1 affected package
curl
| Package | 16.04 LTS |
|---|---|
| curl | Not affected |
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed...
1 affected package
coturn
| Package | 16.04 LTS |
|---|---|
| coturn | Needs evaluation |
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local...
1 affected package
vips
| Package | 16.04 LTS |
|---|---|
| vips | Needs evaluation |