Search CVE reports
1 – 10 of 31992 results
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar...
1 affected package
busybox
| Package | 24.04 LTS |
|---|---|
| busybox | Needs evaluation |
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the...
1 affected package
busybox
| Package | 24.04 LTS |
|---|---|
| busybox | Needs evaluation |
ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce moderate increases (2-4 times above normal) in cpu usage. When having NTS enabled on an ntpd-rs server, an...
1 affected package
rust-ntpd
| Package | 24.04 LTS |
|---|---|
| rust-ntpd | Needs evaluation |
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain...
2 affected packages
golang-github-pion-dtls-v3, golang-github-pion-dtls.v2
| Package | 24.04 LTS |
|---|---|
| golang-github-pion-dtls-v3 | Not in release |
| golang-github-pion-dtls.v2 | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or...
1 affected package
python-cryptography
| Package | 24.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
Not in release
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.
1 affected package
pjproject
| Package | 24.04 LTS |
|---|---|
| pjproject | Not in release |
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
2 affected packages
pillow, pillow-python2
| Package | 24.04 LTS |
|---|---|
| pillow | Not affected |
| pillow-python2 | Not in release |
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution...
2 affected packages
kanboard-cli, python-kanboard
| Package | 24.04 LTS |
|---|---|
| kanboard-cli | Needs evaluation |
| python-kanboard | Needs evaluation |
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit...
1 affected package
node-qs
| Package | 24.04 LTS |
|---|---|
| node-qs | Needs evaluation |
[Unknown description]
2 affected packages
libsoup2.4, libsoup3
| Package | 24.04 LTS |
|---|---|
| libsoup2.4 | Needs evaluation |
| libsoup3 | Needs evaluation |