Search CVE reports
1921 – 1930 of 49226 results
Not in release
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Not in release
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Not in release
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Not in release
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Not in release
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Not in release
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 20.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not in release |
| dotnet10 | Not in release |
Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns...
1 affected package
libprotocol-http2-perl
| Package | 20.04 LTS |
|---|---|
| libprotocol-http2-perl | Needs evaluation |
A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive...
1 affected package
glib2.0
| Package | 20.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with...
1 affected package
389-ds-base
| Package | 20.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent,...
1 affected package
389-ds-base
| Package | 20.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |