Search CVE reports
2051 – 2060 of 45973 results
Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling...
1 affected package
nix
| Package | 24.04 LTS |
|---|---|
| nix | Needs evaluation |
Not in release
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and...
1 affected package
rust-hurl
| Package | 24.04 LTS |
|---|---|
| rust-hurl | Not in release |
GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |