Search CVE reports
5621 – 5630 of 34325 results
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.
1 affected package
poppler
| Package | 22.04 LTS |
|---|---|
| poppler | Fixed |
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results...
1 affected package
libapache2-mod-auth-openidc
| Package | 22.04 LTS |
|---|---|
| libapache2-mod-auth-openidc | Fixed |
In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) without a check for whether the sum of *end and *rdlen...
1 affected package
connman
| Package | 22.04 LTS |
|---|---|
| connman | Needs evaluation |
Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library...
1 affected package
libnet-dropbox-api-perl
| Package | 22.04 LTS |
|---|---|
| libnet-dropbox-api-perl | Needs evaluation |
Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which...
1 affected package
libweb-api-perl
| Package | 22.04 LTS |
|---|---|
| libweb-api-perl | Needs evaluation |
Not in release
Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.
1 affected package
c-blosc2
| Package | 22.04 LTS |
|---|---|
| c-blosc2 | Not in release |
Not in release
gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1...
1 affected package
rust-gix-features
| Package | 22.04 LTS |
|---|---|
| rust-gix-features | Not in release |
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to...
1 affected package
binutils
| Package | 22.04 LTS |
|---|---|
| binutils | Fixed |
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component...
1 affected package
assimp
| Package | 22.04 LTS |
|---|---|
| assimp | Needs evaluation |
Not in release
Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To...
1 affected package
miniflux
| Package | 22.04 LTS |
|---|---|
| miniflux | Not in release |