Search CVE reports
371 – 380 of 47986 results
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...
2 affected packages
glibc, eglibc
| Package | 20.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 20.04 LTS |
|---|---|
| node-cookies | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
mongo-java-driver
| Package | 20.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...
1 affected package
mongo-java-driver
| Package | 20.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
pymongo
| Package | 20.04 LTS |
|---|---|
| pymongo | Needs evaluation |
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...
1 affected package
node-multiparty
| Package | 20.04 LTS |
|---|---|
| node-multiparty | Needs evaluation |
[Unknown description]
1 affected package
libdbi-perl
| Package | 20.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View`...
1 affected package
zoneminder
| Package | 20.04 LTS |
|---|---|
| zoneminder | Needs evaluation |