Search CVE reports


Toggle filters

371 – 380 of 1376 results


CVE-2024-6501

Low priority
Vulnerable

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager...

1 affected package

network-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager Not affected Vulnerable Not affected Not affected Not affected
Show less packages

CVE-0000-0001

Medium priority

Some fixes available 1 of 2

TEST CVE 1

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick — Not affected Fixed Vulnerable Not affected
Show less packages

CVE-2024-24792

Medium priority
Needs evaluation

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

1 affected package

golang-golang-x-image

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-image Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-6388

Medium priority

Some fixes available 5 of 6

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

1 affected package

ubuntu-advantage-desktop-daemon

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ubuntu-advantage-desktop-daemon — Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-39331

Medium priority

Some fixes available 10 of 32

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

6 affected packages

xemacs21, xemacs21-packages, emacs, emacs24, emacs25, org-mode

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xemacs21 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xemacs21-packages Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emacs Not affected Fixed Fixed Fixed —
emacs24 Not in release Not in release Not in release Not in release —
emacs25 Not in release Not in release Not in release Not in release Fixed
org-mode Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-3661

High priority
Ignored

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An...

29 affected packages

connman, gadmin-openvpn-client, gadmin-openvpn-server, golang-github-apparentlymart-go-openvpn-mgmt, kvpnc...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
connman — Ignored Ignored Ignored Ignored
gadmin-openvpn-client — Not in release Not in release Ignored Ignored
gadmin-openvpn-server — Not in release Not in release Ignored Ignored
golang-github-apparentlymart-go-openvpn-mgmt — Ignored Ignored Ignored —
kvpnc — Not in release Not in release Not in release Ignored
libreswan — Ignored Ignored Ignored Ignored
mozillavpn — Not in release Ignored Not in release —
n2n — Ignored Ignored Ignored Ignored
network-manager-fortisslvpn — Ignored Ignored Ignored Ignored
network-manager-iodine — Ignored Ignored Ignored Ignored
network-manager-l2tp — Ignored Ignored Ignored Ignored
network-manager-openconnect — Ignored Ignored Ignored Ignored
network-manager-openvpn — Ignored Ignored Ignored Ignored
network-manager-pptp — Ignored Ignored Ignored Ignored
network-manager-sstp — Ignored Ignored Not in release —
network-manager-strongswan — Ignored Ignored Ignored Ignored
network-manager-vpnc — Ignored Ignored Ignored Ignored
openconnect — Ignored Ignored Ignored Ignored
openfortivpn — Ignored Ignored Ignored Ignored
openvpn — Ignored Ignored Ignored Ignored
pptp-linux — Ignored Ignored Ignored Ignored
pptpd — Not in release Ignored Ignored Ignored
quicktun — Ignored Ignored Ignored Ignored
riseup-vpn — Ignored Not in release Not in release —
softether-vpn — Ignored Ignored Not in release —
sshuttle — Ignored Ignored Ignored Ignored
tinc — Ignored Ignored Ignored Ignored
vpnc — Ignored Ignored Ignored Ignored
wireguard — Ignored Ignored Ignored Ignored
Show all 29 packages Show less packages

CVE-2024-4024

Medium priority
Needs evaluation

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an...

2 affected packages

gitlab-agent, gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
gitlab Not in release Not in release Not in release Not in release —
Show less packages

CVE-2024-4006

Medium priority
Needs evaluation

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes...

2 affected packages

gitlab-agent, gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
gitlab Not in release Not in release Not in release Not in release —
Show less packages

CVE-2024-2829

Medium priority
Needs evaluation

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in...

2 affected packages

gitlab-agent, gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
gitlab Not in release Not in release Not in release Not in release —
Show less packages

CVE-2024-2434

Medium priority
Needs evaluation

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

2 affected packages

gitlab-agent, gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab-agent Needs evaluation Needs evaluation Not in release Not in release —
gitlab Not in release Not in release Not in release Not in release —
Show less packages