Search CVE reports
841 – 850 of 42759 results
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../...
1 affected package
rclone
| Package | 24.04 LTS |
|---|---|
| rclone | Needs evaluation |
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause...
1 affected package
popt
| Package | 24.04 LTS |
|---|---|
| popt | Needs evaluation |
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
1 affected package
genetic
| Package | 24.04 LTS |
|---|---|
| genetic | Needs evaluation |
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles...
1 affected package
rpm
| Package | 24.04 LTS |
|---|---|
| rpm | Needs evaluation |
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the...
1 affected package
bolt
| Package | 24.04 LTS |
|---|---|
| bolt | Needs evaluation |
Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like...
1 affected package
cacti
| Package | 24.04 LTS |
|---|---|
| cacti | Needs evaluation |
tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern...
2 affected packages
goxel, raylib
| Package | 24.04 LTS |
|---|---|
| goxel | Needs evaluation |
| raylib | Not in release |
dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to...
3 affected packages
libchdr, qt6-multimedia, qtads
| Package | 24.04 LTS |
|---|---|
| libchdr | Needs evaluation |
| qt6-multimedia | Needs evaluation |
| qtads | Needs evaluation |