Search CVE reports
191 – 200 of 49308 results
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap...
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory...
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id...
1 affected package
libsolv
| Package | 22.04 LTS |
|---|---|
| libsolv | Needs evaluation |
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color...
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |
Not in release
Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist...
1 affected package
elixir
| Package | 22.04 LTS |
|---|---|
| elixir | Not in release |
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...
4 affected packages
golang-go.crypto, snapd, lxd, google-guest-agent
| Package | 22.04 LTS |
|---|---|
| golang-go.crypto | Needs evaluation |
| snapd | Needs evaluation |
| lxd | Not in release |
| google-guest-agent | Needs evaluation |
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...
1 affected package
golang-github-grpc-ecosystem-grpc-gateway
| Package | 22.04 LTS |
|---|---|
| golang-github-grpc-ecosystem-grpc-gateway | Needs evaluation |
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line...
1 affected package
node-morgan
| Package | 22.04 LTS |
|---|---|
| node-morgan | Needs evaluation |
Not in release
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because...
1 affected package
rust-gix-transport
| Package | 22.04 LTS |
|---|---|
| rust-gix-transport | Not in release |
Not in release
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to...
1 affected package
rust-gix-pack
| Package | 22.04 LTS |
|---|---|
| rust-gix-pack | Not in release |