Search CVE reports
831 – 840 of 32432 results
Not in release
nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffic are affected by a denial of...
1 affected package
rust-ntpd
Package | 22.04 LTS |
---|---|
rust-ntpd | Not in release |
A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is...
1 affected package
node-turndown
Package | 22.04 LTS |
---|---|
node-turndown | Needs evaluation |
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow...
1 affected package
civetweb
Package | 22.04 LTS |
---|---|
civetweb | Needs evaluation |
Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks. After the CVE-2025-24358 fix, a network attacker that places a form...
1 affected package
golang-github-gorilla-csrf
Package | 22.04 LTS |
---|---|
golang-github-gorilla-csrf | Needs evaluation |
A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The...
1 affected package
tcpreplay
Package | 22.04 LTS |
---|---|
tcpreplay | Needs evaluation |
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing...
1 affected package
exiv2
Package | 22.04 LTS |
---|---|
exiv2 | Needs evaluation |
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered...
1 affected package
exiv2
Package | 22.04 LTS |
---|---|
exiv2 | Needs evaluation |
CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for...
1 affected package
libcgi-simple-perl
Package | 22.04 LTS |
---|---|
libcgi-simple-perl | Needs evaluation |
xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This...
1 affected package
golang-github-ulikunitz-xz
Package | 22.04 LTS |
---|---|
golang-github-ulikunitz-xz | Needs evaluation |
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous...
1 affected package
asterisk
Package | 22.04 LTS |
---|---|
asterisk | Needs evaluation |