Search CVE reports
41 – 50 of 26597 results
CVE-2024-43426
Medium priorityNot in release
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
1 affected packages
moodle
Package | 20.04 LTS |
---|---|
moodle | Not in release |
CVE-2024-43425
Medium priorityNot in release
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
1 affected packages
moodle
Package | 20.04 LTS |
---|---|
moodle | Not in release |
CVE-2024-10975
Medium priorityNomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as...
1 affected packages
nomad
Package | 20.04 LTS |
---|---|
nomad | Needs evaluation |
CVE-2024-10963
Medium priorityA vulnerability was found in pam_access due to the improper handling of tokens in access.conf, interpreted as hostnames. This flaw allows attackers to bypass access restrictions by spoofing hostnames, undermining configurations...
1 affected packages
pam
Package | 20.04 LTS |
---|---|
pam | Needs evaluation |
CVE-2024-9902
Medium priorityA flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the...
2 affected packages
ansible, ansible-core
Package | 20.04 LTS |
---|---|
ansible | Needs evaluation |
ansible-core | Not in release |
CVE-2024-51988
Medium priorityRabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid...
1 affected packages
rabbitmq-server
Package | 20.04 LTS |
---|---|
rabbitmq-server | Not affected |
CVE-2024-51755
Medium priorityTwig is a template language for PHP. In a sandbox, and attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method...
2 affected packages
php-twig, twig
Package | 20.04 LTS |
---|---|
php-twig | Needs evaluation |
twig | Not in release |
CVE-2024-51754
Medium priorityTwig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list...
2 affected packages
php-twig, twig
Package | 20.04 LTS |
---|---|
php-twig | Needs evaluation |
twig | Not in release |
CVE-2024-51736
Medium prioritySymphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the...
1 affected packages
symfony
Package | 20.04 LTS |
---|---|
symfony | Not affected |
CVE-2024-50345
Medium prioritysymfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a...
1 affected packages
symfony
Package | 20.04 LTS |
---|---|
symfony | Needs evaluation |