Search CVE reports
1031 – 1040 of 48842 results
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but...
1 affected package
python-anyio
| Package | 24.04 LTS |
|---|---|
| python-anyio | Needs evaluation |
btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the...
1 affected package
btrbk
| Package | 24.04 LTS |
|---|---|
| btrbk | Needs evaluation |
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an...
1 affected package
rsyslog
| Package | 24.04 LTS |
|---|---|
| rsyslog | Not affected |
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...
1 affected package
node-uri-js
| Package | 24.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...
1 affected package
node-braces
| Package | 24.04 LTS |
|---|---|
| node-braces | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Not affected |
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Not affected |
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Vulnerable |
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Vulnerable |
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Vulnerable |