Search CVE reports
651 – 660 of 51201 results
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a...
1 affected package
alsa-lib
| Package | 22.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with...
1 affected package
node-nodemailer
| Package | 22.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |
Not in release
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to...
1 affected package
address-standardizer
| Package | 22.04 LTS |
|---|---|
| address-standardizer | Not in release |
Not in release
procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command...
1 affected package
rust-procs
| Package | 22.04 LTS |
|---|---|
| rust-procs | Not in release |
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected...
1 affected package
haproxy
| Package | 22.04 LTS |
|---|---|
| haproxy | Needs evaluation |
wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc()...
1 affected package
wabt
| Package | 22.04 LTS |
|---|---|
| wabt | Needs evaluation |
In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925....
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Not in release
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can...
1 affected package
zstd-jni-java
| Package | 22.04 LTS |
|---|---|
| zstd-jni-java | Not in release |
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...
1 affected package
sngrep
| Package | 22.04 LTS |
|---|---|
| sngrep | Needs evaluation |
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...
1 affected package
freeciv
| Package | 22.04 LTS |
|---|---|
| freeciv | Needs evaluation |