Search CVE reports
351 – 360 of 52206 results
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over...
2 affected packages
qemu, qemu-hwe
| Package | 22.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | Not in release |
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 22.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 22.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9...
1 affected package
wordpress
| Package | 22.04 LTS |
|---|---|
| wordpress | Needs evaluation |
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to...
1 affected package
gpac
| Package | 22.04 LTS |
|---|---|
| gpac | Needs evaluation |
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow....
1 affected package
poppler
| Package | 22.04 LTS |
|---|---|
| poppler | Needs evaluation |
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can...
1 affected package
poppler
| Package | 22.04 LTS |
|---|---|
| poppler | Needs evaluation |