Search CVE reports
21 – 30 of 36932 results
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the...
1 affected package
rails
| Package | 22.04 LTS |
|---|---|
| rails | Needs evaluation |
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the...
1 affected package
gst-plugins-bad1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting,...
1 affected package
systemd
| Package | 22.04 LTS |
|---|---|
| systemd | Fixed |
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions prior to 5.9.0 are vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when...
1 affected package
cbor2
| Package | 22.04 LTS |
|---|---|
| cbor2 | Needs evaluation |
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation...
1 affected package
binutils
| Package | 22.04 LTS |
|---|---|
| binutils | Needs evaluation |
A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the...
2 affected packages
golang-github-antchfx-xpath, golang-golang-x-vuln
| Package | 22.04 LTS |
|---|---|
| golang-github-antchfx-xpath | Needs evaluation |
| golang-golang-x-vuln | Not in release |
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid...
1 affected package
strongswan
| Package | 22.04 LTS |
|---|---|
| strongswan | Fixed |
Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can...
1 affected package
dnss
| Package | 22.04 LTS |
|---|---|
| dnss | Needs evaluation |