Search CVE reports
3221 – 3230 of 26567 results
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write...
1 affected package
calibre
| Package | 26.04 LTS |
|---|---|
| calibre | Needs evaluation |
Not in release
PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing...
1 affected package
pjproject
| Package | 26.04 LTS |
|---|---|
| pjproject | Not in release |
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption...
1 affected package
golang-github-cilium-ebpf
| Package | 26.04 LTS |
|---|---|
| golang-github-cilium-ebpf | Needs evaluation |
filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if...
1 affected package
golang-filippo-edwards25519
| Package | 26.04 LTS |
|---|---|
| golang-filippo-edwards25519 | Needs evaluation |
Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification...
1 affected package
cosign
| Package | 26.04 LTS |
|---|---|
| cosign | Needs evaluation |
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited...
1 affected package
node-webfont
| Package | 26.04 LTS |
|---|---|
| node-webfont | Needs evaluation |
Not in release
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams...
1 affected package
pjproject
| Package | 26.04 LTS |
|---|---|
| pjproject | Not in release |
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |