Search CVE reports
51 – 60 of 35777 results
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high...
5 affected packages
libpng, firefox, thunderbird, chromium-browser, libpng1.6
| Package | 22.04 LTS |
|---|---|
| libpng | Not in release |
| firefox | Not affected |
| thunderbird | Needs evaluation |
| chromium-browser | Not affected |
| libpng1.6 | Not affected |
A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker...
1 affected package
glib2.0
| Package | 22.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This...
1 affected package
glib2.0
| Package | 22.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory...
1 affected package
glib2.0
| Package | 22.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to...
2 affected packages
libsoup2.4, libsoup3
| Package | 22.04 LTS |
|---|---|
| libsoup2.4 | Needs evaluation |
| libsoup3 | Needs evaluation |
Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc. This issue affects RawTherapee: through 5.11.
1 affected package
rawtherapee
| Package | 22.04 LTS |
|---|---|
| rawtherapee | Needs evaluation |
Not in release
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and...
1 affected package
grafana
| Package | 22.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result,...
1 affected package
grafana
| Package | 22.04 LTS |
|---|---|
| grafana | Not in release |
Not in release
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory....
1 affected package
golang-github-theupdateframework-go-tuf
| Package | 22.04 LTS |
|---|---|
| golang-github-theupdateframework-go-tuf | Not in release |
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can...
1 affected package
python-multipart
| Package | 22.04 LTS |
|---|---|
| python-multipart | Vulnerable |