Search CVE reports
1731 – 1740 of 49194 results
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...
1 affected package
jackson-databind
| Package | 20.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
1 affected package
orthanc
| Package | 20.04 LTS |
|---|---|
| orthanc | Needs evaluation |
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive...
1 affected package
hugo
| Package | 20.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place —...
1 affected package
hugo
| Package | 20.04 LTS |
|---|---|
| hugo | Needs evaluation |
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...
1 affected package
node-compression
| Package | 20.04 LTS |
|---|---|
| node-compression | Needs evaluation |
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client...
1 affected package
net-snmp
| Package | 20.04 LTS |
|---|---|
| net-snmp | Needs evaluation |
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...
2 affected packages
libvirt, libvirt-hwe
| Package | 20.04 LTS |
|---|---|
| libvirt | Needs evaluation |
| libvirt-hwe | — |
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...
1 affected package
node-multiparty
| Package | 20.04 LTS |
|---|---|
| node-multiparty | Needs evaluation |
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
1 affected package
live-boot
| Package | 20.04 LTS |
|---|---|
| live-boot | Needs evaluation |
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |