Search CVE reports
1 – 10 of 32739 results
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.
2 affected packages
xpdf, ipe
| Package | 24.04 LTS |
|---|---|
| xpdf | Needs evaluation |
| ipe | Needs evaluation |
Not in release
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled...
1 affected package
python-memray
| Package | 24.04 LTS |
|---|---|
| python-memray | Not in release |
Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise...
1 affected package
ruby-devise
| Package | 24.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
Not in release
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious...
1 affected package
juju
| Package | 24.04 LTS |
|---|---|
| juju | Not in release |
Not in release
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the...
1 affected package
juju
| Package | 24.04 LTS |
|---|---|
| juju | Not in release |
Not in release
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient...
1 affected package
juju
| Package | 24.04 LTS |
|---|---|
| juju | Not in release |
Not in release
A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the...
1 affected package
juju
| Package | 24.04 LTS |
|---|---|
| juju | Not in release |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a...
1 affected package
imagemagick
| Package | 24.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later...
1 affected package
glances
| Package | 24.04 LTS |
|---|---|
| glances | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those...
1 affected package
glances
| Package | 24.04 LTS |
|---|---|
| glances | Needs evaluation |