Search CVE reports
251 – 260 of 44612 results
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...
1 affected package
clamav
| Package | 20.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...
1 affected package
clamav
| Package | 20.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in...
1 affected package
clamav
| Package | 20.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files...
1 affected package
clamav
| Package | 20.04 LTS |
|---|---|
| clamav | Needs evaluation |
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream...
2 affected packages
smarty3, smarty4
| Package | 20.04 LTS |
|---|---|
| smarty3 | Needs evaluation |
| smarty4 | — |
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before...
2 affected packages
smarty3, smarty4
| Package | 20.04 LTS |
|---|---|
| smarty3 | Needs evaluation |
| smarty4 | — |
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...
1 affected package
libstb
| Package | 20.04 LTS |
|---|---|
| libstb | Needs evaluation |
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...
1 affected package
dracut
| Package | 20.04 LTS |
|---|---|
| dracut | Needs evaluation |
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...
1 affected package
python-h2
| Package | 20.04 LTS |
|---|---|
| python-h2 | Needs evaluation |
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end...
1 affected package
node-re2
| Package | 20.04 LTS |
|---|---|
| node-re2 | Needs evaluation |