Search CVE reports
61 – 70 of 36026 results
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The...
1 affected package
rust-time
| Package | 22.04 LTS |
|---|---|
| rust-time | Needs evaluation |
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...
1 affected package
mupdf
| Package | 22.04 LTS |
|---|---|
| mupdf | Needs evaluation |
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on...
1 affected package
asterisk
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that...
1 affected package
asterisk
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe...
1 affected package
asterisk
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are...
1 affected package
asterisk
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit...
1 affected package
micropython
| Package | 22.04 LTS |
|---|---|
| micropython | Needs evaluation |
A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null pointer dereference. The attack...
1 affected package
libuvc
| Package | 22.04 LTS |
|---|---|
| libuvc | Needs evaluation |
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be...
1 affected package
mruby
| Package | 22.04 LTS |
|---|---|
| mruby | Needs evaluation |
Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using...
1 affected package
node-webpack
| Package | 22.04 LTS |
|---|---|
| node-webpack | Needs evaluation |