Search CVE reports
1181 – 1190 of 43788 results
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads...
1 affected package
horizon
| Package | 24.04 LTS |
|---|---|
| horizon | Needs evaluation |
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local...
1 affected package
open-iscsi
| Package | 24.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with...
1 affected package
designate
| Package | 24.04 LTS |
|---|---|
| designate | Needs evaluation |
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone...
1 affected package
designate
| Package | 24.04 LTS |
|---|---|
| designate | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil...
1 affected package
golang-github-getkin-kin-openapi
| Package | 24.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...
1 affected package
etcd
| Package | 24.04 LTS |
|---|---|
| etcd | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey()...
1 affected package
etcd
| Package | 24.04 LTS |
|---|---|
| etcd | Needs evaluation |