Search CVE reports
121 – 130 of 42759 results
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run,...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell...
1 affected package
kitty
| Package | 24.04 LTS |
|---|---|
| kitty | Needs evaluation |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 24.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not affected |
| freerdp3 | Not affected |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 24.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not affected |
| freerdp3 | Not affected |
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces...
1 affected package
nmap
| Package | 24.04 LTS |
|---|---|
| nmap | Needs evaluation |
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or...
1 affected package
mrtg
| Package | 24.04 LTS |
|---|---|
| mrtg | Needs evaluation |
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on...
1 affected package
kbd
| Package | 24.04 LTS |
|---|---|
| kbd | Needs evaluation |
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent...
1 affected package
zoneminder
| Package | 24.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept...
1 affected package
httpcomponents-core5
| Package | 24.04 LTS |
|---|---|
| httpcomponents-core5 | Needs evaluation |