Search CVE reports
1161 – 1170 of 49291 results
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated...
1 affected package
python-jwcrypto
| Package | 20.04 LTS |
|---|---|
| python-jwcrypto | Needs evaluation |
QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.
2 affected packages
qt6-base, qtbase-opensource-src
| Package | 20.04 LTS |
|---|---|
| qt6-base | — |
| qtbase-opensource-src | Needs evaluation |
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG...
1 affected package
ghostscript
| Package | 20.04 LTS |
|---|---|
| ghostscript | Needs evaluation |