Search CVE reports
1731 – 1740 of 35604 results
(Prometheus is an open-source monitoring system and time series databas ...)
1 affected package
prometheus
| Package | 24.04 LTS |
|---|---|
| prometheus | Needs evaluation |
(Allocation of resources without limits or throttling vulnerability in ...)
1 affected package
bouncycastle
| Package | 24.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
(Improper neutralization of special elements used in an LDAP query ('LD ...)
1 affected package
bouncycastle
| Package | 24.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
Not in release
(In Grafana's alerting system, users with edit permissions for a contac ...)
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
(Insufficient checks of the RMP on host buffer access in IOMMU may allo ...)
1 affected package
amd64-microcode
| Package | 24.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and...
1 affected package
opencryptoki
| Package | 24.04 LTS |
|---|---|
| opencryptoki | Needs evaluation |
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking....
1 affected package
ngtcp2
| Package | 24.04 LTS |
|---|---|
| ngtcp2 | Needs evaluation |
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function...
7 affected packages
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...
| Package | 24.04 LTS |
|---|---|
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Not in release |
| ruby3.2 | Needs evaluation |
| ruby3.3 | Not in release |
| jruby | Needs evaluation |
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to...
1 affected package
protobuf
| Package | 24.04 LTS |
|---|---|
| protobuf | Vulnerable |
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup()...
1 affected package
fio
| Package | 24.04 LTS |
|---|---|
| fio | Needs evaluation |