Search CVE reports
801 – 810 of 26567 results
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality....
1 affected package
eclipse-equinox
| Package | 26.04 LTS |
|---|---|
| eclipse-equinox | Needs evaluation |
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a...
1 affected package
node-ajv
| Package | 26.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled...
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5,...
1 affected package
nix
| Package | 26.04 LTS |
|---|---|
| nix | Needs evaluation |
An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated...
1 affected package
nix
| Package | 26.04 LTS |
|---|---|
| nix | Needs evaluation |
[Integer overflows and out-of-bounds access in MOV/MP4 demuxer]
1 affected package
gst-plugins-good1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-good1.0 | Not affected |
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
1 affected package
postfix
| Package | 26.04 LTS |
|---|---|
| postfix | Fixed |
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
1 affected package
lcms2
| Package | 26.04 LTS |
|---|---|
| lcms2 | Fixed |