Search CVE reports
61 – 70 of 49194 results
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a...
1 affected package
libimager-perl
| Package | 20.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
[usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
1 affected package
usbredir
| Package | 20.04 LTS |
|---|---|
| usbredir | Needs evaluation |
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an...
1 affected package
cockpit
| Package | 20.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...
1 affected package
cockpit
| Package | 20.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...
1 affected package
cockpit
| Package | 20.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 20.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 20.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character...
1 affected package
soupsieve
| Package | 20.04 LTS |
|---|---|
| soupsieve | Needs evaluation |
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC...
1 affected package
soupsieve
| Package | 20.04 LTS |
|---|---|
| soupsieve | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses...
1 affected package
async-http-client
| Package | 20.04 LTS |
|---|---|
| async-http-client | Needs evaluation |