Search CVE reports
1751 – 1760 of 35604 results
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...
1 affected package
rsync
| Package | 24.04 LTS |
|---|---|
| rsync | Vulnerable |
Not in release
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure...
1 affected package
luanti
| Package | 24.04 LTS |
|---|---|
| luanti | Not in release |
Not in release
[Luanti Mod security sandbox escape]
1 affected package
luanti
| Package | 24.04 LTS |
|---|---|
| luanti | Not in release |
[Stack Buffer overflow - Seattle-Filmworks Image]
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
[TIM File Parsing: Stack Out-of-Bounds Write in 4BPP Decode Path]
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
[FITS File Parsing: Integer Overflow in Buffer Allocation Leads to Heap Overflow]
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
[Command injection via malicious Perforce repository definition]
1 affected package
composer
| Package | 24.04 LTS |
|---|---|
| composer | Needs evaluation |
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...
1 affected package
golang-github-docker-spdystream
| Package | 24.04 LTS |
|---|---|
| golang-github-docker-spdystream | Needs evaluation |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...
1 affected package
composer
| Package | 24.04 LTS |
|---|---|
| composer | Needs evaluation |
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |