Search CVE reports
1871 – 1880 of 49226 results
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue...
1 affected package
activemq
| Package | 20.04 LTS |
|---|---|
| activemq | Needs evaluation |
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...
1 affected package
keepass2
| Package | 20.04 LTS |
|---|---|
| keepass2 | Needs evaluation |
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching...
1 affected package
bubblewrap
| Package | 20.04 LTS |
|---|---|
| bubblewrap | Vulnerable |
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
1 affected package
opam
| Package | 20.04 LTS |
|---|---|
| opam | Needs evaluation |
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm...
1 affected package
cjose
| Package | 20.04 LTS |
|---|---|
| cjose | Needs evaluation |
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`,...
1 affected package
cjose
| Package | 20.04 LTS |
|---|---|
| cjose | Needs evaluation |
[Unknown description]
1 affected package
modules
| Package | 20.04 LTS |
|---|---|
| modules | Needs evaluation |
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
1 affected package
dpdk
| Package | 20.04 LTS |
|---|---|
| dpdk | Vulnerable |