Search CVE reports
1 – 10 of 27011 results
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification...
1 affected package
devscripts
Package | 24.04 LTS |
---|---|
devscripts | Needs evaluation |
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
Package | 24.04 LTS |
---|---|
chromium-browser | Not affected |
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...
1 affected package
netavark
Package | 24.04 LTS |
---|---|
netavark | Needs evaluation |
Not in release
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic...
1 affected package
z-push
Package | 24.04 LTS |
---|---|
z-push | Not in release |
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads...
1 affected package
node-yarnpkg
Package | 24.04 LTS |
---|---|
node-yarnpkg | Needs evaluation |
A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory...
1 affected package
binutils
Package | 24.04 LTS |
---|---|
binutils | Needs evaluation |
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null...
1 affected package
binutils
Package | 24.04 LTS |
---|---|
binutils | Needs evaluation |
A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The `soup_header_name_to_string` function does not validate the `name` parameter passed in, and directly...
2 affected packages
libsoup2.4, libsoup3
Package | 24.04 LTS |
---|---|
libsoup2.4 | Vulnerable |
libsoup3 | Vulnerable |
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop...
12 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
Package | 24.04 LTS |
---|---|
python2.7 | Not in release |
python3.4 | Not in release |
python3.5 | Not in release |
python3.6 | Not in release |
python3.7 | Not in release |
python3.8 | Not in release |
python3.9 | Not in release |
python3.10 | Not in release |
python3.11 | Not in release |
python3.12 | Needs evaluation |
python3.13 | Not in release |
python3.14 | Not in release |
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached...
1 affected package
tiff
Package | 24.04 LTS |
---|---|
tiff | Not affected |