Search CVE reports
1751 – 1760 of 26524 results
[FITS File Parsing: Integer Overflow in Buffer Allocation Leads to Heap Overflow]
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Not affected |
[Command injection via malicious Perforce repository definition]
1 affected package
composer
| Package | 26.04 LTS |
|---|---|
| composer | Needs evaluation |
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...
1 affected package
golang-github-docker-spdystream
| Package | 26.04 LTS |
|---|---|
| golang-github-docker-spdystream | Needs evaluation |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...
1 affected package
composer
| Package | 26.04 LTS |
|---|---|
| composer | Needs evaluation |
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Not affected |
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Not affected |
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Not affected |
Not in release
--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product:...
1 affected package
grafana
| Package | 26.04 LTS |
|---|---|
| grafana | Not in release |
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a...
1 affected package
sssd
| Package | 26.04 LTS |
|---|---|
| sssd | Needs evaluation |
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84.
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |