Search CVE reports
871 – 880 of 52944 results
A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion...
1 affected package
yara
| Package | 22.04 LTS |
|---|---|
| yara | Needs evaluation |
An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free...
1 affected package
yara
| Package | 22.04 LTS |
|---|---|
| yara | Needs evaluation |
A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can...
1 affected package
gpac
| Package | 22.04 LTS |
|---|---|
| gpac | Needs evaluation |
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
1 affected package
lwip
| Package | 22.04 LTS |
|---|---|
| lwip | Needs evaluation |
An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components
1 affected package
yaml-cpp
| Package | 22.04 LTS |
|---|---|
| yaml-cpp | Needs evaluation |
Not in release
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height,...
1 affected package
psd-tools
| Package | 22.04 LTS |
|---|---|
| psd-tools | Not in release |
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can...
1 affected package
python-icalendar
| Package | 22.04 LTS |
|---|---|
| python-icalendar | Needs evaluation |
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A...
1 affected package
netdata
| Package | 22.04 LTS |
|---|---|
| netdata | Needs evaluation |
A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a...
2 affected packages
glibc, eglibc
| Package | 22.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active...
1 affected package
wordpress
| Package | 22.04 LTS |
|---|---|
| wordpress | Needs evaluation |