Search CVE reports
1771 – 1780 of 26561 results
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup()...
1 affected package
fio
| Package | 26.04 LTS |
|---|---|
| fio | Needs evaluation |
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for...
1 affected package
radare2
| Package | 26.04 LTS |
|---|---|
| radare2 | Needs evaluation |
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in...
1 affected package
mupdf
| Package | 26.04 LTS |
|---|---|
| mupdf | Needs evaluation |
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...
1 affected package
rsync
| Package | 26.04 LTS |
|---|---|
| rsync | Vulnerable |
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure...
1 affected package
luanti
| Package | 26.04 LTS |
|---|---|
| luanti | Needs evaluation |
Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
1 affected package
luanti
| Package | 26.04 LTS |
|---|---|
| luanti | Needs evaluation |
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...
1 affected package
golang-github-docker-spdystream
| Package | 26.04 LTS |
|---|---|
| golang-github-docker-spdystream | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...
1 affected package
prometheus
| Package | 26.04 LTS |
|---|---|
| prometheus | Needs evaluation |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...
1 affected package
composer
| Package | 26.04 LTS |
|---|---|
| composer | Needs evaluation |