Search CVE reports
151 – 160 of 32559 results
Not in release
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor...
1 affected package
pluxml
| Package | 24.04 LTS |
|---|---|
| pluxml | Not in release |
Not in release
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the...
1 affected package
pluxml
| Package | 24.04 LTS |
|---|---|
| pluxml | Not in release |
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply...
1 affected package
ruby-foreman
| Package | 24.04 LTS |
|---|---|
| ruby-foreman | Needs evaluation |
Not in release
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1)...
1 affected package
libcrypt-sysrandom-xs-perl
| Package | 24.04 LTS |
|---|---|
| libcrypt-sysrandom-xs-perl | Not in release |
A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires...
1 affected package
vips
| Package | 24.04 LTS |
|---|---|
| vips | Needs evaluation |
A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The...
1 affected package
vips
| Package | 24.04 LTS |
|---|---|
| vips | Needs evaluation |
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to...
1 affected package
vips
| Package | 24.04 LTS |
|---|---|
| vips | Needs evaluation |
A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The...
1 affected package
vips
| Package | 24.04 LTS |
|---|---|
| vips | Needs evaluation |
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client...
1 affected package
inetutils
| Package | 24.04 LTS |
|---|---|
| inetutils | Vulnerable |
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This...
1 affected package
vitrage
| Package | 24.04 LTS |
|---|---|
| vitrage | Needs evaluation |