Search CVE reports
241 – 250 of 40186 results
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's...
1 affected package
node-qs
| Package | 22.04 LTS |
|---|---|
| node-qs | Needs evaluation |
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
2 affected packages
u-boot, u-boot-nezha
| Package | 22.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Needs evaluation |
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON...
1 affected package
jsonpickle
| Package | 22.04 LTS |
|---|---|
| jsonpickle | Needs evaluation |
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same...
1 affected package
babl
| Package | 22.04 LTS |
|---|---|
| babl | Needs evaluation |
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
1 affected package
libcrypt-dsa-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-dsa-perl | Needs evaluation |
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
1 affected package
libcrypt-dsa-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-dsa-perl | Needs evaluation |
Not in release
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed...
1 affected package
radare2
| Package | 22.04 LTS |
|---|---|
| radare2 | Not in release |
Not in release
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo...
1 affected package
radare2
| Package | 22.04 LTS |
|---|---|
| radare2 | Not in release |
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes...
2 affected packages
libjwt, libjwt3
| Package | 22.04 LTS |
|---|---|
| libjwt | Needs evaluation |
| libjwt3 | Not in release |
Not in release
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0]...
1 affected package
gitsign
| Package | 22.04 LTS |
|---|---|
| gitsign | Not in release |