Search CVE reports
101 – 110 of 39399 results
(In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Si ...)
1 affected package
zaqar
| Package | 26.04 LTS |
|---|---|
| zaqar | Needs evaluation |
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write,...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |
Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
1 affected package
nanomsg
| Package | 26.04 LTS |
|---|---|
| nanomsg | Needs evaluation |
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only...
1 affected package
swift
| Package | 26.04 LTS |
|---|---|
| swift | Needs evaluation |
(DCMTK through 3.7.0 contains a heap over-read vulnerability in Concate ...)
1 affected package
dcmtk
| Package | 26.04 LTS |
|---|---|
| dcmtk | Needs evaluation |
(sprintf-js through 1.1.3 passes unbounded precision specifiers to toFi ...)
1 affected package
node-sprintf-js
| Package | 26.04 LTS |
|---|---|
| node-sprintf-js | Needs evaluation |
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library...
1 affected package
librsvg
| Package | 26.04 LTS |
|---|---|
| librsvg | Needs evaluation |
In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal....
1 affected package
flatpak
| Package | 26.04 LTS |
|---|---|
| flatpak | Needs evaluation |
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled,...
1 affected package
flatpak
| Package | 26.04 LTS |
|---|---|
| flatpak | Needs evaluation |
(An integer overflow in the BSON document encoding component of the Mon ...)
1 affected package
pymongo
| Package | 26.04 LTS |
|---|---|
| pymongo | Needs evaluation |