Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

171 – 180 of 30617 results

Status is adjusted based on your filters.


CVE-2024-45411

Medium priority
Needs evaluation

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

2 affected packages

php-twig, twig

Package 18.04 LTS
php-twig
twig Needs evaluation
Show less packages

CVE-2024-45296

Medium priority
Needs evaluation

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex...

1 affected packages

node-path-to-regexp

Package 18.04 LTS
node-path-to-regexp Needs evaluation
Show less packages

CVE-2024-24510

Medium priority
Needs evaluation

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

1 affected packages

sogo

Package 18.04 LTS
sogo Needs evaluation
Show less packages

CVE-2024-8373

Medium priority
Needs evaluation

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content...

1 affected packages

angular.js

Package 18.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2024-8372

Medium priority
Needs evaluation

Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content...

1 affected packages

angular.js

Package 18.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2024-45160

Medium priority
Needs evaluation

[Unknown description]

1 affected packages

lemonldap-ng

Package 18.04 LTS
lemonldap-ng Needs evaluation
Show less packages

CVE-2024-42934

Low priority
Needs evaluation

missing check on the authorization type on incoming LAN messages

1 affected packages

openipmi

Package 18.04 LTS
openipmi Needs evaluation
Show less packages

CVE-2024-36138

Medium priority
Needs evaluation

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject...

1 affected packages

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2024-36137

Medium priority
Needs evaluation

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as...

1 affected packages

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2023-46809

Medium priority
Needs evaluation

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1...

1 affected packages

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages