Search CVE reports
281 – 290 of 42497 results
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
1 affected package
virtuoso-opensource
| Package | 22.04 LTS |
|---|---|
| virtuoso-opensource | Needs evaluation |
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
1 affected package
gsasl
| Package | 22.04 LTS |
|---|---|
| gsasl | Needs evaluation |
Not in release
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege...
1 affected package
dhcpcd
| Package | 22.04 LTS |
|---|---|
| dhcpcd | Not in release |
Not in release
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by...
1 affected package
dhcpcd
| Package | 22.04 LTS |
|---|---|
| dhcpcd | Not in release |
Not in release
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...
1 affected package
dhcpcd
| Package | 22.04 LTS |
|---|---|
| dhcpcd | Not in release |
Not in release
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...
1 affected package
dhcpcd
| Package | 22.04 LTS |
|---|---|
| dhcpcd | Not in release |
Not in release
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603...
1 affected package
dhcpcd
| Package | 22.04 LTS |
|---|---|
| dhcpcd | Not in release |
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to...
1 affected package
yt-dlp
| Package | 22.04 LTS |
|---|---|
| yt-dlp | Needs evaluation |
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem,...
1 affected package
yt-dlp
| Package | 22.04 LTS |
|---|---|
| yt-dlp | Needs evaluation |
yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download...
1 affected package
yt-dlp
| Package | 22.04 LTS |
|---|---|
| yt-dlp | Needs evaluation |