Search CVE reports
1311 – 1320 of 43788 results
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 24.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not affected |
| freerdp3 | Not affected |
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent...
1 affected package
zoneminder
| Package | 24.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or...
1 affected package
mrtg
| Package | 24.04 LTS |
|---|---|
| mrtg | Needs evaluation |
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on...
1 affected package
kbd
| Package | 24.04 LTS |
|---|---|
| kbd | Needs evaluation |
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the...
1 affected package
iperf3
| Package | 24.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server....
1 affected package
iperf3
| Package | 24.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.
1 affected package
rlottie
| Package | 24.04 LTS |
|---|---|
| rlottie | Needs evaluation |