Search CVE reports
41 – 50 of 31371 results
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
1 affected package
chromium-browser
Package | 22.04 LTS |
---|---|
chromium-browser | Not affected |
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium...
1 affected package
chromium-browser
Package | 22.04 LTS |
---|---|
chromium-browser | Not affected |
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
1 affected package
chromium-browser
Package | 22.04 LTS |
---|---|
chromium-browser | Not affected |
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
1 affected package
golang-github-cloudflare-circl
Package | 22.04 LTS |
---|---|
golang-github-cloudflare-circl | Needs evaluation |
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It...
5 affected packages
tiff, qtwebengine-opensource-src, texmaker, gdal, neuron
Package | 22.04 LTS |
---|---|
tiff | Needs evaluation |
qtwebengine-opensource-src | Needs evaluation |
texmaker | Needs evaluation |
gdal | Not affected |
neuron | Needs evaluation |
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification...
1 affected package
devscripts
Package | 22.04 LTS |
---|---|
devscripts | Needs evaluation |
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
Package | 22.04 LTS |
---|---|
chromium-browser | Not affected |
Not in release
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...
1 affected package
netavark
Package | 22.04 LTS |
---|---|
netavark | Not in release |
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic...
1 affected package
z-push
Package | 22.04 LTS |
---|---|
z-push | Needs evaluation |
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads...
1 affected package
node-yarnpkg
Package | 22.04 LTS |
---|---|
node-yarnpkg | Needs evaluation |