Search CVE reports
1471 – 1480 of 38833 results
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core...
1 affected package
activemq
| Package | 20.04 LTS |
|---|---|
| activemq | Needs evaluation |
WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See theĀ following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt ...
1 affected package
activemq
| Package | 20.04 LTS |
|---|---|
| activemq | Needs evaluation |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated...
1 affected package
openexr
| Package | 20.04 LTS |
|---|---|
| openexr | Needs evaluation |
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in...
1 affected package
ruby-rails-assets-underscore
| Package | 20.04 LTS |
|---|---|
| ruby-rails-assets-underscore | Needs evaluation |
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files....
5 affected packages
dosbox-x, faudio, octave-ltfat, qtads, roc-toolkit
| Package | 20.04 LTS |
|---|---|
| dosbox-x | — |
| faudio | Needs evaluation |
| octave-ltfat | Needs evaluation |
| qtads | Needs evaluation |
| roc-toolkit | — |
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Not affected |
Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |
two potential OOB memory accesses in virtio-snd
1 affected package
qemu
| Package | 20.04 LTS |
|---|---|
| qemu | Needs evaluation |
two potential OOB memory accesses in virtio-snd
1 affected package
qemu
| Package | 20.04 LTS |
|---|---|
| qemu | Needs evaluation |