Search CVE reports
1 – 10 of 30228 results
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for...
1 affected package
django-allauth
| Package | 24.04 LTS |
|---|---|
| django-allauth | Needs evaluation |
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
1 affected package
django-allauth
| Package | 24.04 LTS |
|---|---|
| django-allauth | Needs evaluation |
Not in release
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted...
1 affected package
elasticsearch
| Package | 24.04 LTS |
|---|---|
| elasticsearch | Not in release |
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By...
1 affected package
libreoffice
| Package | 24.04 LTS |
|---|---|
| libreoffice | Not affected |
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information...
1 affected package
kubernetes
| Package | 24.04 LTS |
|---|---|
| kubernetes | Not affected |
[avoid that non-admin user using other users certificates]
1 affected package
network-manager
| Package | 24.04 LTS |
|---|---|
| network-manager | Vulnerable |
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
1 affected package
uriparser
| Package | 24.04 LTS |
|---|---|
| uriparser | Needs evaluation |
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or...
1 affected package
rust-sequoia-openpgp
| Package | 24.04 LTS |
|---|---|
| rust-sequoia-openpgp | Needs evaluation |
Exim before 4.99.1 allows remote heap corruption that will be further described on 2025-12-18.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Not affected |
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted...
1 affected package
pcsx2
| Package | 24.04 LTS |
|---|---|
| pcsx2 | Needs evaluation |