Search CVE reports
2241 – 2250 of 26524 results
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via...
1 affected package
dnsdist
| Package | 26.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image....
1 affected package
gdk-pixbuf
| Package | 26.04 LTS |
|---|---|
| gdk-pixbuf | Not affected |
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack...
1 affected package
libstb
| Package | 26.04 LTS |
|---|---|
| libstb | Needs evaluation |
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based...
1 affected package
libstb
| Package | 26.04 LTS |
|---|---|
| libstb | Needs evaluation |
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services....
1 affected package
glance
| Package | 26.04 LTS |
|---|---|
| glance | Not affected |
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted...
1 affected package
node-serialize-javascript
| Package | 26.04 LTS |
|---|---|
| node-serialize-javascript | Needs evaluation |
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
2 affected packages
docker.io, docker.io-app
| Package | 26.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
Not in release
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX...
1 affected package
dolibarr
| Package | 26.04 LTS |
|---|---|
| dolibarr | Not in release |
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's...
2 affected packages
docker.io, docker.io-app
| Package | 26.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject alternative name is defined in the...
3 affected packages
botan, botan1.10, botan3
| Package | 26.04 LTS |
|---|---|
| botan | Not in release |
| botan1.10 | Not in release |
| botan3 | Needs evaluation |