Search CVE reports
231 – 240 of 44612 results
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
1 affected package
systemd
| Package | 20.04 LTS |
|---|---|
| systemd | Not affected |
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position...
1 affected package
perl
| Package | 20.04 LTS |
|---|---|
| perl | Needs evaluation |
Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its...
1 affected package
libcrypt-openssl-pkcs12-perl
| Package | 20.04 LTS |
|---|---|
| libcrypt-openssl-pkcs12-perl | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader...
1 affected package
gimp
| Package | 20.04 LTS |
|---|---|
| gimp | Needs evaluation |
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...
1 affected package
bouncycastle
| Package | 20.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply...
1 affected package
kakoune
| Package | 20.04 LTS |
|---|---|
| kakoune | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |