Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

151 – 160 of 26941 results

Status is adjusted based on your filters.


CVE-2024-41679

Medium priority

Not in release

GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.

1 affected packages

glpi

Package 20.04 LTS
glpi Not in release
Show less packages

CVE-2024-52522

Medium priority
Needs evaluation

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged...

1 affected packages

rclone

Package 20.04 LTS
rclone Needs evaluation
Show less packages

CVE-2024-52510

Medium priority
Needs evaluation

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an...

1 affected packages

nextcloud-desktop

Package 20.04 LTS
nextcloud-desktop Needs evaluation
Show less packages

CVE-2024-47759

Medium priority

Not in release

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.

1 affected packages

glpi

Package 20.04 LTS
glpi Not in release
Show less packages

CVE-2024-41678

Medium priority

Not in release

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

1 affected packages

glpi

Package 20.04 LTS
glpi Not in release
Show less packages

CVE-2024-40638

Medium priority

Not in release

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

1 affected packages

glpi

Package 20.04 LTS
glpi Not in release
Show less packages

CVE-2021-1494

Medium priority
Needs evaluation

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect...

1 affected packages

snort

Package 20.04 LTS
snort Needs evaluation
Show less packages

CVE-2024-50986

Medium priority
Needs evaluation

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

1 affected packages

clementine

Package 20.04 LTS
clementine Needs evaluation
Show less packages

CVE-2023-4679

Medium priority
Needs evaluation

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause...

1 affected packages

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2021-3991

Medium priority

Not in release

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access,...

1 affected packages

dolibarr

Package 20.04 LTS
dolibarr Not in release
Show less packages