Search CVE reports
471 – 480 of 35759 results
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource...
1 affected package
avahi
| Package | 22.04 LTS |
|---|---|
| avahi | Fixed |
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record...
1 affected package
avahi
| Package | 22.04 LTS |
|---|---|
| avahi | Fixed |
Not in release
Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.
1 affected package
errands
| Package | 22.04 LTS |
|---|---|
| errands | Not in release |
A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results...
1 affected package
opencolorio
| Package | 22.04 LTS |
|---|---|
| opencolorio | Needs evaluation |
Not in release
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack...
1 affected package
quickjs
| Package | 22.04 LTS |
|---|---|
| quickjs | Not in release |
Not in release
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The...
1 affected package
quickjs
| Package | 22.04 LTS |
|---|---|
| quickjs | Not in release |
Not in release
Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the...
1 affected package
cosign
| Package | 22.04 LTS |
|---|---|
| cosign | Not in release |
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory...
1 affected package
python-virtualenv
| Package | 22.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...
1 affected package
python-filelock
| Package | 22.04 LTS |
|---|---|
| python-filelock | Needs evaluation |
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc...
1 affected package
harfbuzz
| Package | 22.04 LTS |
|---|---|
| harfbuzz | Not affected |