Search CVE reports
3081 – 3090 of 29434 results
Not in release
berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
1 affected package
berkeley-abc
| Package | 24.04 LTS |
|---|---|
| berkeley-abc | Not in release |
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is...
5 affected packages
ruby-webrick, jruby, ruby2.3, ruby2.5, ruby2.7
| Package | 24.04 LTS |
|---|---|
| ruby-webrick | Fixed |
| jruby | Not affected |
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson...
1 affected package
jackson-core
| Package | 24.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
Not in release
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data....
1 affected package
golang-github-go-viper-mapstructure
| Package | 24.04 LTS |
|---|---|
| golang-github-go-viper-mapstructure | Not in release |
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`,...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context....
1 affected package
libssh
| Package | 24.04 LTS |
|---|---|
| libssh | Fixed |
A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads...
1 affected package
libssh
| Package | 24.04 LTS |
|---|---|
| libssh | Not affected |
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0...
1 affected package
libssh
| Package | 24.04 LTS |
|---|---|
| libssh | Fixed |
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but...
1 affected package
libssh
| Package | 24.04 LTS |
|---|---|
| libssh | Fixed |