Search CVE reports
4441 – 4450 of 34325 results
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
3 affected packages
redict, redis, valkey
| Package | 22.04 LTS |
|---|---|
| redict | Not in release |
| redis | Needs evaluation |
| valkey | Not in release |
Not in release
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...
1 affected package
python-signxml
| Package | 22.04 LTS |
|---|---|
| python-signxml | Not in release |
Not in release
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...
1 affected package
python-signxml
| Package | 22.04 LTS |
|---|---|
| python-signxml | Not in release |
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The...
1 affected package
modsecurity-apache
| Package | 22.04 LTS |
|---|---|
| modsecurity-apache | Fixed |
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9,...
1 affected package
node-tar-fs
| Package | 22.04 LTS |
|---|---|
| node-tar-fs | Needs evaluation |
A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.
1 affected package
sslh
| Package | 22.04 LTS |
|---|---|
| sslh | Needs evaluation |
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.
1 affected package
sslh
| Package | 22.04 LTS |
|---|---|
| sslh | Needs evaluation |
quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to...
1 affected package
golang-github-lucas-clemente-quic-go
| Package | 22.04 LTS |
|---|---|
| golang-github-lucas-clemente-quic-go | Needs evaluation |
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to...
1 affected package
catdoc
| Package | 22.04 LTS |
|---|---|
| catdoc | Needs evaluation |
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a...
1 affected package
catdoc
| Package | 22.04 LTS |
|---|---|
| catdoc | Needs evaluation |