Search CVE reports
1751 – 1760 of 60355 results
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second,...
1 affected package
tar
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tar | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods...
2 affected packages
libcommons-lang-java, libcommons-lang3-java
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libcommons-lang-java | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libcommons-lang3-java | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.
1 affected package
pandoc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
pandoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile.This...
1 affected package
qt6-base
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
qt6-base | Needs evaluation | Needs evaluation | — | — |
Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE:...
1 affected package
libgoogle-gson-java
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libgoogle-gson-java | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Not in release
llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in...
1 affected package
llama.cpp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
llama.cpp | Not in release | Not in release | — | — |
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading...
1 affected package
cpp-httplib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cpp-httplib | Needs evaluation | Needs evaluation | — | — |
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This...
1 affected package
cpp-httplib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cpp-httplib | Needs evaluation | Needs evaluation | — | — |
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from...
3 affected packages
tomcat10, tomcat11, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat10 | Vulnerable | Not in release | — | — |
tomcat11 | Not in release | Not in release | — | — |
tomcat9 | Not affected | Vulnerable | Vulnerable | Vulnerable |
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8,...
3 affected packages
tomcat10, tomcat11, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat10 | Vulnerable | Not in release | — | — |
tomcat11 | Not in release | Not in release | — | — |
tomcat9 | Not affected | Vulnerable | Vulnerable | Vulnerable |