Search CVE reports
681 – 690 of 39943 results
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
1 affected package
apache2
| Package | 20.04 LTS |
|---|---|
| apache2 | Not affected |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...
1 affected package
prometheus
| Package | 20.04 LTS |
|---|---|
| prometheus | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...
1 affected package
cimg
| Package | 20.04 LTS |
|---|---|
| cimg | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...
1 affected package
cimg
| Package | 20.04 LTS |
|---|---|
| cimg | Needs evaluation |
Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...
1 affected package
beets
| Package | 20.04 LTS |
|---|---|
| beets | Needs evaluation |
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
2 affected packages
frr, quagga
| Package | 20.04 LTS |
|---|---|
| frr | Needs evaluation |
| quagga | Needs evaluation |
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory...
1 affected package
busybox
| Package | 20.04 LTS |
|---|---|
| busybox | Needs evaluation |
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 2.5.9 before 3.0.0-M3 Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(),...
1 affected package
apache-opennlp
| Package | 20.04 LTS |
|---|---|
| apache-opennlp | Needs evaluation |
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a...
1 affected package
apache-opennlp
| Package | 20.04 LTS |
|---|---|
| apache-opennlp | Needs evaluation |
An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
1 affected package
gobgp
| Package | 20.04 LTS |
|---|---|
| gobgp | Needs evaluation |