Search CVE reports
921 – 930 of 39983 results
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it...
1 affected package
wget2
| Package | 20.04 LTS |
|---|---|
| wget2 | Needs evaluation |
PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmentation fault in...
1 affected package
poppler
| Package | 20.04 LTS |
|---|---|
| poppler | Needs evaluation |
librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the rsvg conversion tool to...
1 affected package
librsvg
| Package | 20.04 LTS |
|---|---|
| librsvg | Not affected |
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed...
1 affected package
mongodb
| Package | 20.04 LTS |
|---|---|
| mongodb | Needs evaluation |
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB...
1 affected package
mongodb
| Package | 20.04 LTS |
|---|---|
| mongodb | Needs evaluation |
An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks...
1 affected package
libsndfile
| Package | 20.04 LTS |
|---|---|
| libsndfile | Needs evaluation |
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. Similar to CVE-2024-11053.
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Vulnerable |
Using libcurl, when a custom `Host:` header is first set for a HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use...
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Not affected |
curl might erroneously pass on credentials for a first proxy to a second proxy.
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Vulnerable |
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Vulnerable |