Search CVE reports
1071 – 1080 of 59781 results
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the...
1 affected package
rabbitmq-server
| Package | 16.04 LTS |
|---|---|
| rabbitmq-server | Needs evaluation |
A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final...
1 affected package
gimp
| Package | 16.04 LTS |
|---|---|
| gimp | Needs evaluation |
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it...
1 affected package
gimp
| Package | 16.04 LTS |
|---|---|
| gimp | Needs evaluation |
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder...
1 affected package
symfony
| Package | 16.04 LTS |
|---|---|
| symfony | Needs evaluation |
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in...
3 affected packages
jline, jline2, jline3
| Package | 16.04 LTS |
|---|---|
| jline | Needs evaluation |
| jline2 | Needs evaluation |
| jline3 | — |
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression...
3 affected packages
jline, jline2, jline3
| Package | 16.04 LTS |
|---|---|
| jline | Needs evaluation |
| jline2 | Needs evaluation |
| jline3 | — |
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text)...
3 affected packages
jline, jline2, jline3
| Package | 16.04 LTS |
|---|---|
| jline | Needs evaluation |
| jline2 | Needs evaluation |
| jline3 | — |
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts...
3 affected packages
jline, jline2, jline3
| Package | 16.04 LTS |
|---|---|
| jline | Needs evaluation |
| jline2 | Needs evaluation |
| jline3 | — |
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |