Search CVE reports
411 – 420 of 32595 results
Not in release
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams...
1 affected package
pjproject
| Package | 24.04 LTS |
|---|---|
| pjproject | Not in release |
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and...
1 affected package
hdf5
| Package | 24.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
1 affected package
qemu
| Package | 24.04 LTS |
|---|---|
| qemu | Needs evaluation |
An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.
1 affected package
golang-github-go-chi-chi
| Package | 24.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately sanitize user-controlled...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute...
1 affected package
spip
| Package | 24.04 LTS |
|---|---|
| spip | Needs evaluation |