Search CVE reports
291 – 300 of 52206 results
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...
1 affected package
cockpit
| Package | 22.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...
1 affected package
cockpit
| Package | 22.04 LTS |
|---|---|
| cockpit | Needs evaluation |
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but...
1 affected package
python-anyio
| Package | 22.04 LTS |
|---|---|
| python-anyio | Needs evaluation |
btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the...
1 affected package
btrbk
| Package | 22.04 LTS |
|---|---|
| btrbk | Needs evaluation |
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an...
1 affected package
rsyslog
| Package | 22.04 LTS |
|---|---|
| rsyslog | Not affected |
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...
1 affected package
node-uri-js
| Package | 22.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...
1 affected package
node-braces
| Package | 22.04 LTS |
|---|---|
| node-braces | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an...
1 affected package
libheif
| Package | 22.04 LTS |
|---|---|
| libheif | Not affected |
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through...
1 affected package
libheif
| Package | 22.04 LTS |
|---|---|
| libheif | Not affected |
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created...
1 affected package
libheif
| Package | 22.04 LTS |
|---|---|
| libheif | Needs evaluation |