Search CVE reports
301 – 310 of 36372 results
Not in release
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard,...
1 affected package
grafana
| Package | 22.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources...
1 affected package
grafana
| Package | 22.04 LTS |
|---|---|
| grafana | Not in release |
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of...
1 affected package
node-markdown-it
| Package | 22.04 LTS |
|---|---|
| node-markdown-it | Needs evaluation |
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit...
1 affected package
node-qs
| Package | 22.04 LTS |
|---|---|
| node-qs | Needs evaluation |
crash via INITIAL packet for the NEW_TOKEN format
1 affected package
haproxy
| Package | 22.04 LTS |
|---|---|
| haproxy | Not affected |
crash in parsing frame type
1 affected package
haproxy
| Package | 22.04 LTS |
|---|---|
| haproxy | Not affected |
Not in release
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted...
1 affected package
keras
| Package | 22.04 LTS |
|---|---|
| keras | Not in release |
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar...
1 affected package
busybox
| Package | 22.04 LTS |
|---|---|
| busybox | Needs evaluation |
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the...
1 affected package
busybox
| Package | 22.04 LTS |
|---|---|
| busybox | Needs evaluation |
Not in release
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain the...
2 affected packages
golang-github-pion-dtls-v3, golang-github-pion-dtls.v2
| Package | 22.04 LTS |
|---|---|
| golang-github-pion-dtls-v3 | Not in release |
| golang-github-pion-dtls.v2 | Not in release |