Search CVE reports
1501 – 1510 of 39983 results
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup()...
1 affected package
fio
| Package | 20.04 LTS |
|---|---|
| fio | Needs evaluation |
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for...
1 affected package
radare2
| Package | 20.04 LTS |
|---|---|
| radare2 | Needs evaluation |
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in...
1 affected package
mupdf
| Package | 20.04 LTS |
|---|---|
| mupdf | Needs evaluation |
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
3 affected packages
libfido2, python-fido2, yubikey-manager
| Package | 20.04 LTS |
|---|---|
| libfido2 | Not affected |
| python-fido2 | Not affected |
| yubikey-manager | Not affected |
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...
1 affected package
rsync
| Package | 20.04 LTS |
|---|---|
| rsync | Vulnerable |
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...
1 affected package
golang-github-docker-spdystream
| Package | 20.04 LTS |
|---|---|
| golang-github-docker-spdystream | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...
1 affected package
prometheus
| Package | 20.04 LTS |
|---|---|
| prometheus | Needs evaluation |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...
1 affected package
composer
| Package | 20.04 LTS |
|---|---|
| composer | Needs evaluation |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating...
1 affected package
composer
| Package | 20.04 LTS |
|---|---|
| composer | Needs evaluation |