Search CVE reports
191 – 200 of 26597 results
CVE-2024-48423
Medium priorityAn issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
3 affected packages
assimp, qt6-3d, qt6-quick3d
Package | 20.04 LTS |
---|---|
assimp | Needs evaluation |
qt6-3d | Not in release |
qt6-quick3d | Not in release |
CVE-2024-48208
Medium prioritypure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
1 affected packages
pure-ftpd
Package | 20.04 LTS |
---|---|
pure-ftpd | Needs evaluation |
CVE-2024-47883
Medium priorityNot in release
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or...
1 affected packages
openrefine-butterfly
Package | 20.04 LTS |
---|---|
openrefine-butterfly | Not in release |
CVE-2024-47882
Medium priorityNot in release
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML...
1 affected packages
openrefine
Package | 20.04 LTS |
---|---|
openrefine | Not in release |
CVE-2024-47881
Medium priorityNot in release
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration,...
1 affected packages
openrefine
Package | 20.04 LTS |
---|---|
openrefine | Not in release |
CVE-2024-47880
Medium priorityNot in release
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken...
1 affected packages
openrefine
Package | 20.04 LTS |
---|---|
openrefine | Not in release |
CVE-2024-47879
Medium priorityNot in release
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an...
1 affected packages
openrefine
Package | 20.04 LTS |
---|---|
openrefine | Not in release |
CVE-2024-47878
Medium priorityNot in release
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without...
1 affected packages
openrefine
Package | 20.04 LTS |
---|---|
openrefine | Not in release |
CVE-2024-46478
Medium priorityHTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
1 affected packages
htmldoc
Package | 20.04 LTS |
---|---|
htmldoc | Needs evaluation |
CVE-2024-8312
Medium priorityNot in release
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
1 affected packages
gitlab
Package | 20.04 LTS |
---|---|
gitlab | Not in release |