Search CVE reports
551 – 560 of 47099 results
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...
1 affected package
network-manager-l2tp
| Package | 24.04 LTS |
|---|---|
| network-manager-l2tp | Needs evaluation |
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or...
12 affected packages
pypy3, python2.7, python3.4, python3.5, python3.6...
| Package | 24.04 LTS |
|---|---|
| pypy3 | Needs evaluation |
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Needs evaluation |
| python3.14 | Not in release |
PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a...
1 affected package
pymupdf
| Package | 24.04 LTS |
|---|---|
| pymupdf | Needs evaluation |
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and...
1 affected package
allure
| Package | 24.04 LTS |
|---|---|
| allure | Needs evaluation |
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer()...
1 affected package
allure
| Package | 24.04 LTS |
|---|---|
| allure | Needs evaluation |
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine...
3 affected packages
containerd, containerd-app, containerd-stable
| Package | 24.04 LTS |
|---|---|
| containerd | Needs evaluation |
| containerd-app | Needs evaluation |
| containerd-stable | Not in release |
A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the...
1 affected package
binutils
| Package | 24.04 LTS |
|---|---|
| binutils | Needs evaluation |
A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff...
1 affected package
binutils
| Package | 24.04 LTS |
|---|---|
| binutils | Needs evaluation |
A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The...
1 affected package
binutils
| Package | 24.04 LTS |
|---|---|
| binutils | Needs evaluation |
A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires...
1 affected package
binutils
| Package | 24.04 LTS |
|---|---|
| binutils | Needs evaluation |