Search CVE reports
1471 – 1480 of 39983 results
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote....
1 affected package
miniupnpd
| Package | 20.04 LTS |
|---|---|
| miniupnpd | Needs evaluation |
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds...
3 affected packages
libcoap, libcoap2, libcoap3
| Package | 20.04 LTS |
|---|---|
| libcoap | — |
| libcoap2 | Needs evaluation |
| libcoap3 | — |
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can...
1 affected package
radare2
| Package | 20.04 LTS |
|---|---|
| radare2 | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters,...
1 affected package
xrdp
| Package | 20.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a...
1 affected package
xrdp
| Package | 20.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When...
1 affected package
xrdp
| Package | 20.04 LTS |
|---|---|
| xrdp | Needs evaluation |
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering...
2 affected packages
firebird3.0, firebird4.0
| Package | 20.04 LTS |
|---|---|
| firebird3.0 | Needs evaluation |
| firebird4.0 | — |
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length...
2 affected packages
firebird3.0, firebird4.0
| Package | 20.04 LTS |
|---|---|
| firebird3.0 | Needs evaluation |
| firebird4.0 | — |
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing...
2 affected packages
firebird3.0, firebird4.0
| Package | 20.04 LTS |
|---|---|
| firebird3.0 | Needs evaluation |
| firebird4.0 | — |
xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining buffer...
1 affected package
xrdp
| Package | 20.04 LTS |
|---|---|
| xrdp | Needs evaluation |