Search CVE reports
621 – 630 of 36525 results
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
Not in release
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session...
1 affected package
liblivemedia
| Package | 24.04 LTS |
|---|---|
| liblivemedia | Not in release |
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...
1 affected package
kitty
| Package | 24.04 LTS |
|---|---|
| kitty | Needs evaluation |
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object...
1 affected package
ruby-faraday
| Package | 24.04 LTS |
|---|---|
| ruby-faraday | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately....
1 affected package
kitty
| Package | 24.04 LTS |
|---|---|
| kitty | Needs evaluation |
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies....
9 affected packages
mozjs68, firefox, thunderbird, mozjs38, mozjs52...
| Package | 24.04 LTS |
|---|---|
| mozjs68 | Not in release |
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Ignored |
| mozjs115 | Ignored |
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class...
1 affected package
apscheduler
| Package | 24.04 LTS |
|---|---|
| apscheduler | Needs evaluation |
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation...
1 affected package
libnginx-mod-js
| Package | 24.04 LTS |
|---|---|
| libnginx-mod-js | Needs evaluation |