Search CVE reports
851 – 860 of 32962 results
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a...
1 affected package
pglogical
| Package | 26.04 LTS |
|---|---|
| pglogical | Needs evaluation |
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection...
1 affected package
criu
| Package | 26.04 LTS |
|---|---|
| criu | Needs evaluation |
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This...
1 affected package
ruby-sqlite3
| Package | 26.04 LTS |
|---|---|
| ruby-sqlite3 | Needs evaluation |
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference...
1 affected package
ruby-sqlite3
| Package | 26.04 LTS |
|---|---|
| ruby-sqlite3 | Needs evaluation |
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server...
1 affected package
ruby-oauth
| Package | 26.04 LTS |
|---|---|
| ruby-oauth | Needs evaluation |
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request...
1 affected package
ruby-oauth2
| Package | 26.04 LTS |
|---|---|
| ruby-oauth2 | Needs evaluation |
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a...
2 affected packages
golang-github-gopacket-gopacket, gopacket
| Package | 26.04 LTS |
|---|---|
| golang-github-gopacket-gopacket | Needs evaluation |
| gopacket | Needs evaluation |
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes...
2 affected packages
golang-github-gopacket-gopacket, gopacket
| Package | 26.04 LTS |
|---|---|
| golang-github-gopacket-gopacket | Needs evaluation |
| gopacket | Needs evaluation |
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a...
1 affected package
sg3-utils
| Package | 26.04 LTS |
|---|---|
| sg3-utils | Needs evaluation |
tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due...
1 affected package
rust-tiny-http
| Package | 26.04 LTS |
|---|---|
| rust-tiny-http | Needs evaluation |