Search CVE reports
361 – 370 of 33493 results
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
1 affected package
inkscape
| Package | 24.04 LTS |
|---|---|
| inkscape | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence...
1 affected package
node-brace-expansion
| Package | 24.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar...
1 affected package
calibre
| Package | 24.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's...
1 affected package
calibre
| Package | 24.04 LTS |
|---|---|
| calibre | Needs evaluation |
Not in release
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
A resample query can be used to trigger out-of-memory crashes in Grafana.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to...
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |