Search CVE reports
351 – 360 of 49232 results
A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By...
1 affected package
network-manager-iodine
| Package | 24.04 LTS |
|---|---|
| network-manager-iodine | Needs evaluation |
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user...
1 affected package
kitty
| Package | 24.04 LTS |
|---|---|
| kitty | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when an existing AMQP connection refreshes from an OAuth...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacker-controlled runtime parameter values into non-garbage-collected Erlang atoms before bounding them or...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI...
1 affected package
rabbitmq-server
| Package | 24.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |