Search CVE reports
801 – 810 of 38817 results
Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a...
1 affected package
libsereal-encoder-perl
| Package | 20.04 LTS |
|---|---|
| libsereal-encoder-perl | Not affected |
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image....
1 affected package
gdk-pixbuf
| Package | 20.04 LTS |
|---|---|
| gdk-pixbuf | Needs evaluation |
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based...
1 affected package
libstb
| Package | 20.04 LTS |
|---|---|
| libstb | Needs evaluation |
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services....
1 affected package
glance
| Package | 20.04 LTS |
|---|---|
| glance | Fixed |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer...
1 affected package
python-cryptography
| Package | 20.04 LTS |
|---|---|
| python-cryptography | Not affected |
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
2 affected packages
docker.io, docker.io-app
| Package | 20.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's...
2 affected packages
docker.io, docker.io-app
| Package | 20.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject alternative name is defined in the...
3 affected packages
botan, botan1.10, botan3
| Package | 20.04 LTS |
|---|---|
| botan | Needs evaluation |
| botan1.10 | — |
| botan3 | — |
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP...
3 affected packages
botan, botan1.10, botan3
| Package | 20.04 LTS |
|---|---|
| botan | Needs evaluation |
| botan1.10 | — |
| botan3 | — |
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length...
3 affected packages
botan, botan1.10, botan3
| Package | 20.04 LTS |
|---|---|
| botan | Needs evaluation |
| botan1.10 | — |
| botan3 | — |