Search CVE reports
791 – 800 of 45567 results
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB,...
1 affected package
dia
| Package | 24.04 LTS |
|---|---|
| dia | Needs evaluation |
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
1 affected package
stomper
| Package | 24.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously...
1 affected package
stomper
| Package | 24.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its...
1 affected package
stomper
| Package | 24.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of...
1 affected package
stomper
| Package | 24.04 LTS |
|---|---|
| stomper | Needs evaluation |
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in...
1 affected package
stomper
| Package | 24.04 LTS |
|---|---|
| stomper | Needs evaluation |
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used...
2 affected packages
u-boot, u-boot-nezha
| Package | 24.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Needs evaluation |
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by...
2 affected packages
u-boot, u-boot-nezha
| Package | 24.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Needs evaluation |
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel...
3 affected packages
libjpeg-turbo, libjpeg6b, libjpeg9
| Package | 24.04 LTS |
|---|---|
| libjpeg-turbo | Needs evaluation |
| libjpeg6b | Needs evaluation |
| libjpeg9 | Needs evaluation |