Search CVE reports
541 – 550 of 36841 results
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path...
1 affected package
erlang
| Package | 22.04 LTS |
|---|---|
| erlang | Needs evaluation |
This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
1 affected package
node-bn.js
| Package | 22.04 LTS |
|---|---|
| node-bn.js | Needs evaluation |
uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH,...
1 affected package
golang-refraction-networking-utls
| Package | 22.04 LTS |
|---|---|
| golang-refraction-networking-utls | Needs evaluation |
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many...
1 affected package
node-minimatch
| Package | 22.04 LTS |
|---|---|
| node-minimatch | Needs evaluation |
uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism...
1 affected package
golang-refraction-networking-utls
| Package | 22.04 LTS |
|---|---|
| golang-refraction-networking-utls | Needs evaluation |
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction...
1 affected package
node-tar
| Package | 22.04 LTS |
|---|---|
| node-tar | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that...
1 affected package
calibre
| Package | 22.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write...
1 affected package
calibre
| Package | 22.04 LTS |
|---|---|
| calibre | Needs evaluation |
Not in release
PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing...
1 affected package
pjproject
| Package | 22.04 LTS |
|---|---|
| pjproject | Not in release |
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption...
1 affected package
golang-github-cilium-ebpf
| Package | 22.04 LTS |
|---|---|
| golang-github-cilium-ebpf | Needs evaluation |