Search CVE reports
31 – 40 of 42899 results
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state...
1 affected package
libarchive
| Package | 22.04 LTS |
|---|---|
| libarchive | Needs evaluation |
CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which...
1 affected package
libcryptx-perl
| Package | 22.04 LTS |
|---|---|
| libcryptx-perl | Needs evaluation |
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when...
1 affected package
p11-kit
| Package | 22.04 LTS |
|---|---|
| p11-kit | Vulnerable |
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host...
1 affected package
node-ajv
| Package | 22.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
[Unknown description]
1 affected package
graphicsmagick
| Package | 22.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an...
1 affected package
yelp
| Package | 22.04 LTS |
|---|---|
| yelp | Needs evaluation |
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array....
1 affected package
util-linux
| Package | 22.04 LTS |
|---|---|
| util-linux | Needs evaluation |
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as...
1 affected package
libcss-minifier-xs-perl
| Package | 22.04 LTS |
|---|---|
| libcss-minifier-xs-perl | Needs evaluation |
Not in release
A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes...
4 affected packages
llvm-toolchain-18, llvm-toolchain-19, llvm-toolchain-21, llvm-toolchain-22
| Package | 22.04 LTS |
|---|---|
| llvm-toolchain-18 | Not in release |
| llvm-toolchain-19 | Not in release |
| llvm-toolchain-21 | Not in release |
| llvm-toolchain-22 | Not in release |
Not in release
A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in...
4 affected packages
llvm-toolchain-18, llvm-toolchain-19, llvm-toolchain-21, llvm-toolchain-22
| Package | 22.04 LTS |
|---|---|
| llvm-toolchain-18 | Not in release |
| llvm-toolchain-19 | Not in release |
| llvm-toolchain-21 | Not in release |
| llvm-toolchain-22 | Not in release |