Search CVE reports
201 – 210 of 47939 results
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling...
1 affected package
fluidsynth
| Package | 24.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one...
1 affected package
fluidsynth
| Package | 24.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its...
1 affected package
fluidsynth
| Package | 24.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the...
1 affected package
fluidsynth
| Package | 24.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe...
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions...
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash...
1 affected package
suricata
| Package | 24.04 LTS |
|---|---|
| suricata | Needs evaluation |
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed...
1 affected package
c-ares
| Package | 24.04 LTS |
|---|---|
| c-ares | Needs evaluation |
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...
1 affected package
c-ares
| Package | 24.04 LTS |
|---|---|
| c-ares | Needs evaluation |
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never...
1 affected package
python-anyio
| Package | 24.04 LTS |
|---|---|
| python-anyio | Needs evaluation |