Search CVE reports
2291 – 2300 of 45973 results
Not in release
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
1 affected package
zabbix
| Package | 24.04 LTS |
|---|---|
| zabbix | Not in release |
Not in release
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
1 affected package
zabbix
| Package | 24.04 LTS |
|---|---|
| zabbix | Not in release |
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
[Unknown description]
1 affected package
suricata-update
| Package | 24.04 LTS |
|---|---|
| suricata-update | Needs evaluation |
[Unknown description]
1 affected package
open-iscsi
| Package | 24.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
[Unknown description]
1 affected package
open-iscsi
| Package | 24.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
Not in release
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call...
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash...
1 affected package
hashcat
| Package | 24.04 LTS |
|---|---|
| hashcat | Needs evaluation |
Not in release
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing...
1 affected package
deskflow
| Package | 24.04 LTS |
|---|---|
| deskflow | Not in release |
Not in release
Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so...
1 affected package
deskflow
| Package | 24.04 LTS |
|---|---|
| deskflow | Not in release |