Search CVE reports
31 – 40 of 37910 results
CVE-2024-8647
Medium priorityAn issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the...
1 affected package
gitlab
Package | 16.04 LTS |
---|---|
gitlab | Ignored |
CVE-2024-8233
Medium priorityAn issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.
1 affected package
gitlab
Package | 16.04 LTS |
---|---|
gitlab | Ignored |
CVE-2024-8179
Medium priorityAn issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.
1 affected package
gitlab
Package | 16.04 LTS |
---|---|
gitlab | Ignored |
CVE-2024-50339
Medium priorityGLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17...
1 affected package
glpi
Package | 16.04 LTS |
---|---|
glpi | Needs evaluation |
CVE-2024-47835
Medium priorityGStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find...
2 affected packages
gst-plugins-base0.10, gst-plugins-base1.0
Package | 16.04 LTS |
---|---|
gst-plugins-base0.10 | Needs evaluation |
gst-plugins-base1.0 | Needs evaluation |
CVE-2024-47834
Medium priorityGStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 16.04 LTS |
---|---|
gst-plugins-good0.10 | Needs evaluation |
gst-plugins-good1.0 | Needs evaluation |
CVE-2024-47778
Medium priorityGStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 16.04 LTS |
---|---|
gst-plugins-good0.10 | Needs evaluation |
gst-plugins-good1.0 | Needs evaluation |
CVE-2024-47777
Medium priorityGStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 16.04 LTS |
---|---|
gst-plugins-good0.10 | Needs evaluation |
gst-plugins-good1.0 | Needs evaluation |
CVE-2024-47776
Medium priorityGStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a discrepancy between the size of the...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 16.04 LTS |
---|---|
gst-plugins-good0.10 | Needs evaluation |
gst-plugins-good1.0 | Needs evaluation |
CVE-2024-47775
Medium priorityGStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function does not check that the buffer buf...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
Package | 16.04 LTS |
---|---|
gst-plugins-good0.10 | Needs evaluation |
gst-plugins-good1.0 | Needs evaluation |