Search CVE reports
291 – 300 of 44358 results
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing...
1 affected package
cjson
| Package | 20.04 LTS |
|---|---|
| cjson | Needs evaluation |
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from...
1 affected package
node-postcss
| Package | 20.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and...
1 affected package
node-postcss
| Package | 20.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
2 affected packages
open-iscsi, open-isns
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
| open-isns | Needs evaluation |
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When...
1 affected package
bison
| Package | 20.04 LTS |
|---|---|
| bison | Needs evaluation |
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML...
1 affected package
bison
| Package | 20.04 LTS |
|---|---|
| bison | Needs evaluation |
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform...
1 affected package
binutils
| Package | 20.04 LTS |
|---|---|
| binutils | Needs evaluation |
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |