Search CVE reports
1 – 10 of 47071 results
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031...
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
1 affected package
freeipmi
| Package | 20.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
2 affected packages
xpdf, ipe
| Package | 20.04 LTS |
|---|---|
| xpdf | — |
| ipe | Needs evaluation |
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries...
1 affected package
ruby-zip
| Package | 20.04 LTS |
|---|---|
| ruby-zip | Needs evaluation |
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid...
1 affected package
node-node-forge
| Package | 20.04 LTS |
|---|---|
| node-node-forge | Needs evaluation |
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace...
1 affected package
gst-plugins-base1.0
| Package | 20.04 LTS |
|---|---|
| gst-plugins-base1.0 | Needs evaluation |