Search CVE reports
1 – 10 of 46882 results
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
1 affected package
openvpn
| Package | 22.04 LTS |
|---|---|
| openvpn | Needs evaluation |
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via...
1 affected package
openvpn
| Package | 22.04 LTS |
|---|---|
| openvpn | Needs evaluation |
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID...
1 affected package
capstone
| Package | 22.04 LTS |
|---|---|
| capstone | Needs evaluation |
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large...
1 affected package
capstone
| Package | 22.04 LTS |
|---|---|
| capstone | Needs evaluation |
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...
1 affected package
golang-golang-x-image
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-image | Needs evaluation |
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |
Not in release
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many...
1 affected package
podman
| Package | 22.04 LTS |
|---|---|
| podman | Not in release |
[Unknown description]
1 affected package
inetutils
| Package | 22.04 LTS |
|---|---|
| inetutils | Needs evaluation |
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration...
1 affected package
lvm2
| Package | 22.04 LTS |
|---|---|
| lvm2 | Needs evaluation |
Not in release
(An issue in MongoDB Server's aggregation framework could allow an unau ...)
1 affected package
mongodb
| Package | 22.04 LTS |
|---|---|
| mongodb | Not in release |