Search CVE reports
521 – 530 of 41184 results
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on...
1 affected package
gpac
| Package | 20.04 LTS |
|---|---|
| gpac | Needs evaluation |
LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight...
6 affected packages
italc, libvncserver, tightvnc, veyon, vino, x11vnc
| Package | 20.04 LTS |
|---|---|
| italc | — |
| libvncserver | Needs evaluation |
| tightvnc | Needs evaluation |
| veyon | Needs evaluation |
| vino | Needs evaluation |
| x11vnc | Needs evaluation |
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as...
1 affected package
rabbitmq-server
| Package | 20.04 LTS |
|---|---|
| rabbitmq-server | Not affected |
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength...
1 affected package
libusb
| Package | 20.04 LTS |
|---|---|
| libusb | Not affected |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in...
1 affected package
erlang
| Package | 20.04 LTS |
|---|---|
| erlang | Needs evaluation |
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In...
1 affected package
erlang
| Package | 20.04 LTS |
|---|---|
| erlang | Needs evaluation |
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than...
1 affected package
libusb
| Package | 20.04 LTS |
|---|---|
| libusb | Not affected |
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to...
1 affected package
libhttp-daemon-perl
| Package | 20.04 LTS |
|---|---|
| libhttp-daemon-perl | Fixed |
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in...
2 affected packages
libio-compress-perl, perl
| Package | 20.04 LTS |
|---|---|
| libio-compress-perl | Needs evaluation |
| perl | Needs evaluation |
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP...
2 affected packages
libio-compress-perl, perl
| Package | 20.04 LTS |
|---|---|
| libio-compress-perl | Needs evaluation |
| perl | Needs evaluation |