Search CVE reports
831 – 840 of 44358 results
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across...
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious...
1 affected package
gpsd
| Package | 20.04 LTS |
|---|---|
| gpsd | Needs evaluation |
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod...
1 affected package
kubernetes
| Package | 20.04 LTS |
|---|---|
| kubernetes | Not affected |
A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size....
1 affected package
gdk-pixbuf
| Package | 20.04 LTS |
|---|---|
| gdk-pixbuf | Needs evaluation |
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By...
1 affected package
node-brace-expansion
| Package | 20.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject...
3 affected packages
qt4-x11, qt6-base, qtbase-opensource-src
| Package | 20.04 LTS |
|---|---|
| qt4-x11 | — |
| qt6-base | — |
| qtbase-opensource-src | Needs evaluation |
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A...
2 affected packages
cups-filters, libcupsfilters
| Package | 20.04 LTS |
|---|---|
| cups-filters | Needs evaluation |
| libcupsfilters | — |
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
1 affected package
pdns-recursor
| Package | 20.04 LTS |
|---|---|
| pdns-recursor | Needs evaluation |
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
1 affected package
pdns-recursor
| Package | 20.04 LTS |
|---|---|
| pdns-recursor | Needs evaluation |
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired...
1 affected package
pdns-recursor
| Package | 20.04 LTS |
|---|---|
| pdns-recursor | Needs evaluation |