Search CVE reports
1631 – 1640 of 43643 results
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...
2 affected packages
markdown, python-markdown
| Package | 24.04 LTS |
|---|---|
| markdown | Needs evaluation |
| python-markdown | Needs evaluation |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |
Not in release
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens)...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
Not in release
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
Not in release
llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
Not in release
llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
Not in release
llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |