Search CVE reports
381 – 390 of 49652 results
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 20.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | — |
| emacs25 | — |
lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
1 affected package
lwip
| Package | 20.04 LTS |
|---|---|
| lwip | Needs evaluation |
wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied...
1 affected package
wlc
| Package | 20.04 LTS |
|---|---|
| wlc | Needs evaluation |
An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().
1 affected package
mpack
| Package | 20.04 LTS |
|---|---|
| mpack | Needs evaluation |
A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion...
1 affected package
yara
| Package | 20.04 LTS |
|---|---|
| yara | Needs evaluation |
An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free...
1 affected package
yara
| Package | 20.04 LTS |
|---|---|
| yara | Needs evaluation |
A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can...
1 affected package
gpac
| Package | 20.04 LTS |
|---|---|
| gpac | Needs evaluation |
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
1 affected package
lwip
| Package | 20.04 LTS |
|---|---|
| lwip | Needs evaluation |
An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components
1 affected package
yaml-cpp
| Package | 20.04 LTS |
|---|---|
| yaml-cpp | Needs evaluation |
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can...
1 affected package
python-icalendar
| Package | 20.04 LTS |
|---|---|
| python-icalendar | Needs evaluation |