Search CVE reports
721 – 730 of 33861 results
Not in release
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
A resample query can be used to trigger out-of-memory crashes in Grafana.
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to...
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid...
1 affected package
grafana
| Package | 24.04 LTS |
|---|---|
| grafana | Not in release |
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to...
1 affected package
firewalld
| Package | 24.04 LTS |
|---|---|
| firewalld | Needs evaluation |
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
1 affected package
ocaml
| Package | 24.04 LTS |
|---|---|
| ocaml | Needs evaluation |
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following...
1 affected package
cpp-httplib
| Package | 24.04 LTS |
|---|---|
| cpp-httplib | Needs evaluation |
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated...
1 affected package
mapserver
| Package | 24.04 LTS |
|---|---|
| mapserver | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has...
2 affected packages
pypdf, pypdf2
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
| pypdf2 | Needs evaluation |