Search CVE reports
1031 – 1040 of 59781 results
hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.
1 affected package
hiredis
| Package | 16.04 LTS |
|---|---|
| hiredis | Needs evaluation |
libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which...
1 affected package
libde265
| Package | 16.04 LTS |
|---|---|
| libde265 | Needs evaluation |
libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
1 affected package
libsndfile
| Package | 16.04 LTS |
|---|---|
| libsndfile | Needs evaluation |
ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for an invalid edge pattern, and...
1 affected package
zbar
| Package | 16.04 LTS |
|---|---|
| zbar | Needs evaluation |
libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not...
1 affected package
vips
| Package | 16.04 LTS |
|---|---|
| vips | Needs evaluation |
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers...
1 affected package
ndpi
| Package | 16.04 LTS |
|---|---|
| ndpi | Needs evaluation |
An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation...
1 affected package
mpack
| Package | 16.04 LTS |
|---|---|
| mpack | Needs evaluation |
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
1 affected package
mbedtls
| Package | 16.04 LTS |
|---|---|
| mbedtls | Needs evaluation |
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the...
1 affected package
rabbitmq-server
| Package | 16.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that...
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 16.04 LTS |
|---|---|
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | Needs evaluation |
| python3.6 | — |
| python3.7 | — |
| python3.8 | — |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |