Search CVE reports
71 – 80 of 27730 results
predictable WebSocket mask
1 affected package
curl
Package | 24.04 LTS |
---|---|
curl | Vulnerable |
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS |
---|---|
ffmpeg | Needs evaluation |
libav | Not in release |
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory....
1 affected package
libssh
Package | 24.04 LTS |
---|---|
libssh | Needs evaluation |
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data...
2 affected packages
sqlite, sqlite3
Package | 24.04 LTS |
---|---|
sqlite | Not in release |
sqlite3 | Fixed |
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
1 affected package
libcpanel-json-xs-perl
Package | 24.04 LTS |
---|---|
libcpanel-json-xs-perl | Fixed |
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
1 affected package
libjson-xs-perl
Package | 24.04 LTS |
---|---|
libjson-xs-perl | Fixed |
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain...
1 affected package
node-sanitize-html
Package | 24.04 LTS |
---|---|
node-sanitize-html | Needs evaluation |
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to...
1 affected package
node-sanitize-html
Package | 24.04 LTS |
---|---|
node-sanitize-html | Needs evaluation |
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through...
1 affected package
jackrabbit
Package | 24.04 LTS |
---|---|
jackrabbit | Needs evaluation |
In the Linux kernel, the following vulnerability has been resolved: Revert "fs/ntfs3: Replace inode_trylock with inode_lock" This reverts commit 69505fe98f198ee813898cbcaf6770949636430b. Initially, conditional lock acquisition was...
144 affected packages
linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...
Package | 24.04 LTS |
---|---|
linux | Vulnerable |
linux-hwe | Not in release |
linux-hwe-5.4 | Not in release |
linux-hwe-5.8 | Not in release |
linux-hwe-5.11 | Not in release |
linux-hwe-5.13 | Not in release |
linux-hwe-5.15 | Not in release |
linux-hwe-5.19 | Not in release |
linux-hwe-6.2 | Not in release |
linux-hwe-6.5 | Not in release |
linux-hwe-6.8 | Not in release |
linux-hwe-6.11 | Ignored |
linux-hwe-6.14 | Vulnerable |
linux-hwe-edge | Not in release |
linux-lts-xenial | Not in release |
linux-kvm | Not in release |
linux-allwinner-5.19 | Not in release |
linux-aws | Vulnerable |
linux-aws-5.0 | Not in release |
linux-aws-5.3 | Not in release |
linux-aws-5.4 | Not in release |
linux-aws-5.8 | Not in release |
linux-aws-5.11 | Not in release |
linux-aws-5.13 | Not in release |
linux-aws-5.15 | Not in release |
linux-aws-5.19 | Not in release |
linux-aws-6.2 | Not in release |
linux-aws-6.5 | Not in release |
linux-aws-6.8 | Not in release |
linux-aws-6.14 | Vulnerable |
linux-aws-hwe | Not in release |
linux-azure | Vulnerable |
linux-azure-4.15 | Not in release |
linux-azure-5.3 | Not in release |
linux-azure-5.4 | Not in release |
linux-azure-5.8 | Not in release |
linux-azure-5.11 | Not in release |
linux-azure-5.13 | Not in release |
linux-azure-5.15 | Not in release |
linux-azure-5.19 | Not in release |
linux-azure-6.2 | Not in release |
linux-azure-6.5 | Not in release |
linux-azure-6.8 | Not in release |
linux-azure-6.11 | Ignored |
linux-azure-fde | Not in release |
linux-azure-fde-5.15 | Not in release |
linux-azure-fde-5.19 | Not in release |
linux-azure-fde-6.2 | Not in release |
linux-azure-nvidia | Vulnerable |
linux-bluefield | Not in release |
linux-azure-edge | Not in release |
linux-fips | Not in release |
linux-aws-fips | Not in release |
linux-azure-fips | Not in release |
linux-gcp-fips | Not in release |
linux-gcp | Vulnerable |
linux-gcp-4.15 | Not in release |
linux-gcp-5.3 | Not in release |
linux-gcp-5.4 | Not in release |
linux-gcp-5.8 | Not in release |
linux-gcp-5.11 | Not in release |
linux-gcp-5.13 | Not in release |
linux-gcp-5.15 | Not in release |
linux-gcp-5.19 | Not in release |
linux-gcp-6.2 | Not in release |
linux-gcp-6.5 | Not in release |
linux-gcp-6.8 | Not in release |
linux-gcp-6.11 | Ignored |
linux-gcp-6.14 | Vulnerable |
linux-gke | Vulnerable |
linux-gke-4.15 | Not in release |
linux-gke-5.4 | Not in release |
linux-gke-5.15 | Not in release |
linux-gkeop | Vulnerable |
linux-gkeop-5.4 | Not in release |
linux-gkeop-5.15 | Not in release |
linux-ibm | Vulnerable |
linux-ibm-5.4 | Not in release |
linux-ibm-5.15 | Not in release |
linux-ibm-6.8 | Not in release |
linux-intel-5.13 | Not in release |
linux-intel-iotg | Not in release |
linux-intel-iotg-5.15 | Not in release |
linux-iot | Not in release |
linux-intel-iot-realtime | Not in release |
linux-lowlatency | Vulnerable |
linux-lowlatency-hwe-5.15 | Not in release |
linux-lowlatency-hwe-5.19 | Not in release |
linux-lowlatency-hwe-6.2 | Not in release |
linux-lowlatency-hwe-6.5 | Not in release |
linux-lowlatency-hwe-6.8 | Not in release |
linux-lowlatency-hwe-6.11 | Ignored |
linux-nvidia | Vulnerable |
linux-nvidia-6.2 | Not in release |
linux-nvidia-6.5 | Not in release |
linux-nvidia-6.8 | Not in release |
linux-nvidia-6.11 | Vulnerable |
linux-nvidia-lowlatency | Vulnerable |
linux-nvidia-tegra | Vulnerable |
linux-nvidia-tegra-5.15 | Not in release |
linux-nvidia-tegra-igx | Not in release |
linux-oracle | Vulnerable |
linux-oracle-5.0 | Not in release |
linux-oracle-5.3 | Not in release |
linux-oracle-5.4 | Not in release |
linux-oracle-5.8 | Not in release |
linux-oracle-5.11 | Not in release |
linux-oracle-5.13 | Not in release |
linux-oracle-5.15 | Not in release |
linux-oracle-6.5 | Not in release |
linux-oracle-6.8 | Not in release |
linux-oracle-6.14 | Vulnerable |
linux-oem | Not in release |
linux-oem-5.6 | Not in release |
linux-oem-5.10 | Not in release |
linux-oem-5.13 | Not in release |
linux-oem-5.14 | Not in release |
linux-oem-5.17 | Not in release |
linux-oem-6.0 | Not in release |
linux-oem-6.1 | Not in release |
linux-oem-6.5 | Not in release |
linux-oem-6.8 | Ignored |
linux-oem-6.11 | Vulnerable |
linux-oem-6.14 | Vulnerable |
linux-raspi | Vulnerable |
linux-raspi2 | Not in release |
linux-raspi-5.4 | Not in release |
linux-raspi-realtime | Vulnerable |
linux-realtime | Vulnerable |
linux-realtime-6.8 | Not in release |
linux-realtime-6.14 | Vulnerable |
linux-riscv | Ignored |
linux-riscv-5.8 | Not in release |
linux-riscv-5.11 | Not in release |
linux-riscv-5.15 | Not in release |
linux-riscv-5.19 | Not in release |
linux-riscv-6.5 | Not in release |
linux-riscv-6.8 | Not in release |
linux-riscv-6.14 | Vulnerable |
linux-starfive-5.19 | Not in release |
linux-starfive-6.2 | Not in release |
linux-starfive-6.5 | Not in release |
linux-xilinx-zynqmp | Not in release |
linux-intel | Ignored |