Search CVE reports
261 – 270 of 42497 results
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(),...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only...
1 affected package
jackson-databind
| Package | 22.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing....
1 affected package
gst-plugins-bad1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from...
1 affected package
gst-plugins-bad1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
1 affected package
gnupg2
| Package | 22.04 LTS |
|---|---|
| gnupg2 | Needs evaluation |