Search CVE reports
421 – 430 of 47986 results
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
1 affected package
pcre2
| Package | 20.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client...
1 affected package
net-snmp
| Package | 20.04 LTS |
|---|---|
| net-snmp | Needs evaluation |
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding...
1 affected package
mongodb
| Package | 20.04 LTS |
|---|---|
| mongodb | Needs evaluation |
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...
2 affected packages
glibc, eglibc
| Package | 20.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds...
1 affected package
gst-plugins-good1.0
| Package | 20.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 20.04 LTS |
|---|---|
| node-cookies | Needs evaluation |