Search CVE reports


Toggle filters

101 – 110 of 526 results


CVE-2024-45239

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-45238

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-45237

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-45236

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-45235

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-45234

Medium priority

Some fixes available 3 of 4

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This...

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-43791

Medium priority
Needs evaluation

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This...

1 affected package

ruby-request-store

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-request-store Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-43411

Negligible priority
Vulnerable

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over...

4 affected packages

ckeditor, ldap-account-manager, request-tracker4, ckeditor3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not in release Vulnerable Not affected Not affected Not affected
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor3 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-43407

Medium priority
Needs evaluation

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in...

5 affected packages

geshi, ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
geshi Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not in release Not affected Not affected Not affected Not affected
ckeditor3 Not in release Not affected Not affected Not affected Not affected
ldap-account-manager Not affected Not affected Not affected Not affected Not affected
request-tracker4 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-35198

Medium priority
Ignored

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not...

1 affected package

pytorch

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Not affected Not in release
Show less packages