Search CVE reports
11 – 20 of 36525 results
(A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the ...)
1 affected package
dcmtk
| Package | 24.04 LTS |
|---|---|
| dcmtk | Needs evaluation |
Not in release
A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The...
1 affected package
dolibarr
| Package | 24.04 LTS |
|---|---|
| dolibarr | Not in release |
(A NULL pointer dereference in GPAC MP4Box: when parsing certain trunca ...)
1 affected package
gpac
| Package | 24.04 LTS |
|---|---|
| gpac | Needs evaluation |
(Null pointer dereference in add_ca_certs() in Cesanta Mongoose before ...)
2 affected packages
mongoose, swupdate
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
| swupdate | Needs evaluation |
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted...
1 affected package
keystone
| Package | 24.04 LTS |
|---|---|
| keystone | Needs evaluation |
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary...
1 affected package
keystone
| Package | 24.04 LTS |
|---|---|
| keystone | Needs evaluation |
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the...
1 affected package
keystone
| Package | 24.04 LTS |
|---|---|
| keystone | Needs evaluation |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in...
1 affected package
erlang
| Package | 24.04 LTS |
|---|---|
| erlang | Needs evaluation |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to...
1 affected package
erlang
| Package | 24.04 LTS |
|---|---|
| erlang | Needs evaluation |
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In...
1 affected package
erlang
| Package | 24.04 LTS |
|---|---|
| erlang | Needs evaluation |