Search CVE reports
271 – 280 of 42336 results
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position...
1 affected package
perl
| Package | 24.04 LTS |
|---|---|
| perl | Needs evaluation |
Not in release
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be...
1 affected package
dolibarr
| Package | 24.04 LTS |
|---|---|
| dolibarr | Not in release |
Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its...
1 affected package
libcrypt-openssl-pkcs12-perl
| Package | 24.04 LTS |
|---|---|
| libcrypt-openssl-pkcs12-perl | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...
1 affected package
bouncycastle
| Package | 24.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
Not in release
Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager...
1 affected package
ruby-ruby-lsp
| Package | 24.04 LTS |
|---|---|
| ruby-ruby-lsp | Not in release |
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply...
1 affected package
kakoune
| Package | 24.04 LTS |
|---|---|
| kakoune | Needs evaluation |
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login...
1 affected package
jupyterhub
| Package | 24.04 LTS |
|---|---|
| jupyterhub | Needs evaluation |
Not in release
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |