Search CVE reports
421 – 430 of 40627 results
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...
1 affected package
libheif
| Package | 22.04 LTS |
|---|---|
| libheif | Needs evaluation |
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as...
1 affected package
jupyterhub
| Package | 22.04 LTS |
|---|---|
| jupyterhub | Needs evaluation |
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...
1 affected package
ruby-devise
| Package | 22.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.
2 affected packages
golang-golang-x-sys, google-guest-agent
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-sys | Needs evaluation |
| google-guest-agent | Needs evaluation |
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...
1 affected package
pcmanfm-qt
| Package | 22.04 LTS |
|---|---|
| pcmanfm-qt | Needs evaluation |
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...
7 affected packages
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...
| Package | 22.04 LTS |
|---|---|
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Needs evaluation |
| ruby3.2 | Not in release |
| ruby3.3 | Not in release |
| jruby | Not in release |
In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model...
1 affected package
armnn
| Package | 22.04 LTS |
|---|---|
| armnn | Needs evaluation |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...
1 affected package
golang-golang-x-net-dev
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |