Search CVE reports
81 – 90 of 40097 results
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
1 affected package
xen
| Package | 20.04 LTS |
|---|---|
| xen | Needs evaluation |
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
1 affected package
php-mongodb
| Package | 20.04 LTS |
|---|---|
| php-mongodb | Needs evaluation |
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target =...
1 affected package
rust-openssl
| Package | 20.04 LTS |
|---|---|
| rust-openssl | Needs evaluation |
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the...
1 affected package
libsixel
| Package | 20.04 LTS |
|---|---|
| libsixel | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression...
1 affected package
openimageio
| Package | 20.04 LTS |
|---|---|
| openimageio | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes buffer size as const int bufsize = w...
1 affected package
openimageio
| Package | 20.04 LTS |
|---|---|
| openimageio | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp:469 (mixed RLE) and :345 (pure RLE) do not clamp...
1 affected package
openimageio
| Package | 20.04 LTS |
|---|---|
| openimageio | Needs evaluation |
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any...
1 affected package
docker-registry
| Package | 20.04 LTS |
|---|---|
| docker-registry | Needs evaluation |
CWE-601 URL redirection to untrusted site ('open redirect')
1 affected package
ntopng
| Package | 20.04 LTS |
|---|---|
| ntopng | Needs evaluation |
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via...
1 affected package
ruby-css-parser
| Package | 20.04 LTS |
|---|---|
| ruby-css-parser | Needs evaluation |