Search CVE reports
1071 – 1080 of 41031 results
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the...
1 affected package
lwip
| Package | 22.04 LTS |
|---|---|
| lwip | Needs evaluation |
Not in release
Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating...
1 affected package
mongodb
| Package | 22.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is...
1 affected package
libcrypt-openssl-pkcs12-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-openssl-pkcs12-perl | Not in release |
Not in release
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap...
1 affected package
libcrypt-openssl-pkcs12-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-openssl-pkcs12-perl | Not in release |
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's...
1 affected package
node-qs
| Package | 22.04 LTS |
|---|---|
| node-qs | Needs evaluation |
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
2 affected packages
u-boot, u-boot-nezha
| Package | 22.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Needs evaluation |
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON...
1 affected package
jsonpickle
| Package | 22.04 LTS |
|---|---|
| jsonpickle | Needs evaluation |
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same...
1 affected package
babl
| Package | 22.04 LTS |
|---|---|
| babl | Needs evaluation |
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
1 affected package
libcrypt-dsa-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-dsa-perl | Needs evaluation |
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
1 affected package
libcrypt-dsa-perl
| Package | 22.04 LTS |
|---|---|
| libcrypt-dsa-perl | Needs evaluation |