Search CVE reports
951 – 960 of 48842 results
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check...
1 affected package
usbredir
| Package | 24.04 LTS |
|---|---|
| usbredir | Needs evaluation |
[pre-authentication global buffer overflow]
1 affected package
ppp
| Package | 24.04 LTS |
|---|---|
| ppp | Needs evaluation |
Not in release
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with...
1 affected package
cri-o
| Package | 24.04 LTS |
|---|---|
| cri-o | Not in release |
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media...
1 affected package
php-getid3
| Package | 24.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject...
1 affected package
php-getid3
| Package | 24.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 24.04 LTS |
|---|---|
| kamailio | Needs evaluation |
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to...
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
1 affected package
exim4
| Package | 24.04 LTS |
|---|---|
| exim4 | Needs evaluation |