Search CVE reports
1651 – 1660 of 37432 results
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate...
1 affected package
python-jwcrypto
| Package | 26.04 LTS |
|---|---|
| python-jwcrypto | Needs evaluation |
cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In...
1 affected package
cpp-httplib
| Package | 26.04 LTS |
|---|---|
| cpp-httplib | Needs evaluation |
cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a...
1 affected package
cpp-httplib
| Package | 26.04 LTS |
|---|---|
| cpp-httplib | Needs evaluation |
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing...
1 affected package
zoneminder
| Package | 26.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers...
1 affected package
ceph
| Package | 26.04 LTS |
|---|---|
| ceph | Needs evaluation |
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key...
1 affected package
ceph
| Package | 26.04 LTS |
|---|---|
| ceph | Needs evaluation |
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides...
1 affected package
ceph
| Package | 26.04 LTS |
|---|---|
| ceph | Needs evaluation |
An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |