Search CVE reports
1091 – 1100 of 38020 results
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
1 affected package
pcre2
| Package | 26.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds...
1 affected package
gst-plugins-good1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling...
1 affected package
mruby
| Package | 26.04 LTS |
|---|---|
| mruby | Needs evaluation |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that...
1 affected package
gobgp
| Package | 26.04 LTS |
|---|---|
| gobgp | Needs evaluation |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data...
1 affected package
gobgp
| Package | 26.04 LTS |
|---|---|
| gobgp | Needs evaluation |
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name...
1 affected package
psd-tools
| Package | 26.04 LTS |
|---|---|
| psd-tools | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can...
1 affected package
suricata
| Package | 26.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms....
1 affected package
suricata
| Package | 26.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of...
1 affected package
suricata
| Package | 26.04 LTS |
|---|---|
| suricata | Needs evaluation |