Search CVE reports
541 – 550 of 33763 results
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the...
1 affected package
dnsdist
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a...
1 affected package
dnsdist
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration...
1 affected package
dnsdist
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via...
1 affected package
dnsdist
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a...
1 affected package
libsereal-encoder-perl
| Package | 24.04 LTS |
|---|---|
| libsereal-encoder-perl | Not affected |
Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a...
1 affected package
libsereal-encoder-perl
| Package | 24.04 LTS |
|---|---|
| libsereal-encoder-perl | Not affected |
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image....
1 affected package
gdk-pixbuf
| Package | 24.04 LTS |
|---|---|
| gdk-pixbuf | Fixed |
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based...
1 affected package
libstb
| Package | 24.04 LTS |
|---|---|
| libstb | Needs evaluation |
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services....
1 affected package
glance
| Package | 24.04 LTS |
|---|---|
| glance | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer...
1 affected package
python-cryptography
| Package | 24.04 LTS |
|---|---|
| python-cryptography | Not affected |