Search CVE reports
201 – 210 of 27004 results
An rsync daemon configured with "use chroot = no" is exposed to a time-of-check / time-of-use race on parent path components. A local attacker with write access to a module can replace a parent directory component with a symlink...
1 affected package
rsync
| Package | 26.04 LTS |
|---|---|
| rsync | Fixed |
Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For...
1 affected package
libtemplate-perl
| Package | 26.04 LTS |
|---|---|
| libtemplate-perl | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...
1 affected package
kitty
| Package | 26.04 LTS |
|---|---|
| kitty | Needs evaluation |
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object...
1 affected package
ruby-faraday
| Package | 26.04 LTS |
|---|---|
| ruby-faraday | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor...
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |