Search CVE reports
11 – 20 of 46511 results
(A security vulnerability has been detected in GPAC up to f1219cde. Aff ...)
1 affected package
gpac
| Package | 24.04 LTS |
|---|---|
| gpac | Needs evaluation |
(A vulnerability was identified in GPAC up to f1219cde. The impacted el ...)
1 affected package
gpac
| Package | 24.04 LTS |
|---|---|
| gpac | Needs evaluation |
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...
1 affected package
sngrep
| Package | 24.04 LTS |
|---|---|
| sngrep | Needs evaluation |
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...
1 affected package
freeciv
| Package | 24.04 LTS |
|---|---|
| freeciv | Needs evaluation |
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame...
1 affected package
freeciv
| Package | 24.04 LTS |
|---|---|
| freeciv | Needs evaluation |
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000...
1 affected package
msgpack-java
| Package | 24.04 LTS |
|---|---|
| msgpack-java | Needs evaluation |
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested...
1 affected package
msgpack-java
| Package | 24.04 LTS |
|---|---|
| msgpack-java | Needs evaluation |
Not in release
aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing...
1 affected package
aiosmtplib
| Package | 24.04 LTS |
|---|---|
| aiosmtplib | Not in release |
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
1 affected package
ironic
| Package | 24.04 LTS |
|---|---|
| ironic | Needs evaluation |