Search CVE reports
11 – 20 of 22110 results
CVE-2024-55553
Medium priorityIn FRRouting (FRR) before 10.3, it is possible for an attacker to trigger repeated RIB revalidation by sending approximately 500 RPKI updates, potentially leading to prolonged revalidation times and a Denial of Service (DoS) scenario.
2 affected packages
frr, quagga
Package | 24.04 LTS |
---|---|
frr | Needs evaluation |
quagga | Not in release |
CVE-2024-51741
Medium priorityRedis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The...
3 affected packages
redict, redis, valkey
Package | 24.04 LTS |
---|---|
redict | Not in release |
redis | Needs evaluation |
valkey | Needs evaluation |
CVE-2024-46981
Medium priorityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is...
3 affected packages
redict, redis, valkey
Package | 24.04 LTS |
---|---|
redict | Not in release |
redis | Needs evaluation |
valkey | Needs evaluation |
CVE-2024-12426
Medium priorityExposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values,...
1 affected package
libreoffice
Package | 24.04 LTS |
---|---|
libreoffice | Needs evaluation |
CVE-2024-12425
Medium priorityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with...
1 affected package
libreoffice
Package | 24.04 LTS |
---|---|
libreoffice | Needs evaluation |
CVE-2023-6605
Medium priorityA flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS |
---|---|
ffmpeg | Needs evaluation |
libav | Not in release |
CVE-2023-6604
Medium priorityA flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted...
2 affected packages
ffmpeg, libav
Package | 24.04 LTS |
---|---|
ffmpeg | Needs evaluation |
libav | Not in release |
CVE-2023-6601
Medium priorityA flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS |
---|---|
ffmpeg | Needs evaluation |
libav | Not in release |
CVE-2025-22376
Medium priorityIn Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.
1 affected package
libnet-oauth-perl
Package | 24.04 LTS |
---|---|
libnet-oauth-perl | Needs evaluation |
CVE-2024-9264
Medium priorityNot in release
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection...
1 affected package
grafana
Package | 24.04 LTS |
---|---|
grafana | Not in release |