Search CVE reports
221 – 230 of 48104 results
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Not affected |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS |
|---|---|
| expat | Needs evaluation |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Not in release |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Not in release |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | Not in release |
| cableswig | Not in release |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | Not in release |
| smart | Not in release |
| firefox | Not affected |
| thunderbird | Not affected |
| libxmltok | Needs evaluation |
Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name)...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value...
1 affected package
libdbi-perl
| Package | 24.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...
2 affected packages
varnish, vinyl-cache
| Package | 24.04 LTS |
|---|---|
| varnish | Needs evaluation |
| vinyl-cache | Not in release |