Search CVE reports
21 – 30 of 33266 results
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...
1 affected package
golang-github-go-git-go-git
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
Not in release
Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...
1 affected package
check-mk
| Package | 24.04 LTS |
|---|---|
| check-mk | Not in release |
An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap...
1 affected package
mupdf
| Package | 24.04 LTS |
|---|---|
| mupdf | Needs evaluation |
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple...
1 affected package
scitokens-cpp
| Package | 24.04 LTS |
|---|---|
| scitokens-cpp | Needs evaluation |
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes...
1 affected package
scitokens-cpp
| Package | 24.04 LTS |
|---|---|
| scitokens-cpp | Needs evaluation |
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only...
1 affected package
node-lodash
| Package | 24.04 LTS |
|---|---|
| node-lodash | Needs evaluation |
(Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
1 affected package
onnx
| Package | 24.04 LTS |
|---|---|
| onnx | Needs evaluation |
(Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a ...)
1 affected package
mbedtls
| Package | 24.04 LTS |
|---|---|
| mbedtls | Needs evaluation |
(Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.)
1 affected package
mbedtls
| Package | 24.04 LTS |
|---|---|
| mbedtls | Needs evaluation |
(Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow ...)
1 affected package
mbedtls
| Package | 24.04 LTS |
|---|---|
| mbedtls | Needs evaluation |