Search CVE reports
771 – 780 of 37431 results
Not in release
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential...
1 affected package
gitlab
| Package | 22.04 LTS |
|---|---|
| gitlab | Not in release |
Some fixes available 1 of 3
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 22.04 LTS |
|---|---|
| webkitgtk | Not in release |
| webkit2gtk | Fixed |
| qtwebkit-source | Not in release |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a...
1 affected package
mold
| Package | 22.04 LTS |
|---|---|
| mold | Needs evaluation |
Not in release
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been...
1 affected package
quickjs
| Package | 22.04 LTS |
|---|---|
| quickjs | Not in release |
Not in release
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints....
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11...
1 affected package
consul
| Package | 22.04 LTS |
|---|---|
| consul | Needs evaluation |
yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended timestamp extra field parser within the getLastModDate() function. The while loop condition checks cursor...
1 affected package
node-yauzl
| Package | 22.04 LTS |
|---|---|
| node-yauzl | Needs evaluation |
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack...
1 affected package
libheif
| Package | 22.04 LTS |
|---|---|
| libheif | Not affected |
Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing...
1 affected package
python-tornado
| Package | 22.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the...
1 affected package
black
| Package | 22.04 LTS |
|---|---|
| black | Needs evaluation |