Search CVE reports
251 – 260 of 49443 results
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to...
1 affected package
libjackson-json-java
| Package | 22.04 LTS |
|---|---|
| libjackson-json-java | Needs evaluation |
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how...
1 affected package
popt
| Package | 22.04 LTS |
|---|---|
| popt | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes...
2 affected packages
pypdf, pypdf2
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |
| pypdf2 | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields....
1 affected package
python-tornado
| Package | 22.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Not in release
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
1 affected package
webkitgtk
| Package | 22.04 LTS |
|---|---|
| webkitgtk | Not in release |
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...
1 affected package
gdb
| Package | 22.04 LTS |
|---|---|
| gdb | Needs evaluation |
A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The...
1 affected package
flvmeta
| Package | 22.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow....
1 affected package
flvmeta
| Package | 22.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to...
1 affected package
liburi-perl
| Package | 22.04 LTS |
|---|---|
| liburi-perl | Needs evaluation |
Not in release
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed...
1 affected package
rust-zbus-polkit
| Package | 22.04 LTS |
|---|---|
| rust-zbus-polkit | Not in release |