Search CVE reports
1 – 10 of 32445 results
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core...
1 affected package
activemq
| Package | 24.04 LTS |
|---|---|
| activemq | Needs evaluation |
Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining...
1 affected package
activemq
| Package | 24.04 LTS |
|---|---|
| activemq | Needs evaluation |
Not in release
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to...
1 affected package
joserfc
| Package | 24.04 LTS |
|---|---|
| joserfc | Not in release |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in...
1 affected package
ruby-rails-assets-underscore
| Package | 24.04 LTS |
|---|---|
| ruby-rails-assets-underscore | Needs evaluation |
dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV...
5 affected packages
dosbox-x, faudio, octave-ltfat, qtads, roc-toolkit
| Package | 24.04 LTS |
|---|---|
| dosbox-x | Needs evaluation |
| faudio | Needs evaluation |
| octave-ltfat | Needs evaluation |
| qtads | Needs evaluation |
| roc-toolkit | Needs evaluation |
DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution....
1 affected package
biosig
| Package | 24.04 LTS |
|---|---|
| biosig | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An...
1 affected package
biosig
| Package | 24.04 LTS |
|---|---|
| biosig | Needs evaluation |