Search CVE reports
821 – 830 of 36929 results
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...
1 affected package
libheif
| Package | 24.04 LTS |
|---|---|
| libheif | Needs evaluation |
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as...
1 affected package
jupyterhub
| Package | 24.04 LTS |
|---|---|
| jupyterhub | Needs evaluation |
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...
1 affected package
ruby-devise
| Package | 24.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.
2 affected packages
golang-golang-x-sys, google-guest-agent
| Package | 24.04 LTS |
|---|---|
| golang-golang-x-sys | Needs evaluation |
| google-guest-agent | Needs evaluation |
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...
1 affected package
pcmanfm-qt
| Package | 24.04 LTS |
|---|---|
| pcmanfm-qt | Needs evaluation |
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...
7 affected packages
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...
| Package | 24.04 LTS |
|---|---|
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Not in release |
| ruby3.2 | Needs evaluation |
| ruby3.3 | Not in release |
| jruby | Needs evaluation |
In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model...
1 affected package
armnn
| Package | 24.04 LTS |
|---|---|
| armnn | Needs evaluation |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 24.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 24.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |