Search CVE reports
1761 – 1770 of 49194 results
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...
1 affected package
mongo-java-driver
| Package | 20.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}}...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or...
1 affected package
tesseract
| Package | 20.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted...
1 affected package
tesseract
| Package | 20.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars...
1 affected package
tesseract
| Package | 20.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model...
1 affected package
tesseract
| Package | 20.04 LTS |
|---|---|
| tesseract | Needs evaluation |