Search CVE reports
191 – 200 of 31781 results
In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between vCPUs, this prevents the guest kernel correctly...
1 affected package
xen
| Package | 24.04 LTS |
|---|---|
| xen | Needs evaluation |
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the...
1 affected package
xen
| Package | 24.04 LTS |
|---|---|
| xen | Needs evaluation |
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution....
1 affected package
phpunit
| Package | 24.04 LTS |
|---|---|
| phpunit | Needs evaluation |
Not in release
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with...
1 affected package
pytorch
| Package | 24.04 LTS |
|---|---|
| pytorch | Not in release |
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the...
2 affected packages
pypdf, pypdf2
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
| pypdf2 | Needs evaluation |
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).
1 affected package
gnupg2
| Package | 24.04 LTS |
|---|---|
| gnupg2 | Not affected |
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
1 affected package
gnupg2
| Package | 24.04 LTS |
|---|---|
| gnupg2 | Vulnerable |
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged...
1 affected package
gnupg2
| Package | 24.04 LTS |
|---|---|
| gnupg2 | Not affected |
Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x86-64 platforms with AVX, Wasmtime's compilation of the `f64.copysign` WebAssembly instruction with Cranelift...
1 affected package
rust-wasmtime
| Package | 24.04 LTS |
|---|---|
| rust-wasmtime | Needs evaluation |
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions...
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |