Search CVE reports
641 – 650 of 49955 results
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...
1 affected package
prometheus
| Package | 16.04 LTS |
|---|---|
| prometheus | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...
1 affected package
cimg
| Package | 16.04 LTS |
|---|---|
| cimg | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...
1 affected package
cimg
| Package | 16.04 LTS |
|---|---|
| cimg | Needs evaluation |
Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...
1 affected package
beets
| Package | 16.04 LTS |
|---|---|
| beets | Needs evaluation |
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
2 affected packages
frr, quagga
| Package | 16.04 LTS |
|---|---|
| frr | — |
| quagga | Needs evaluation |
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory...
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
2 affected packages
frr, quagga
| Package | 16.04 LTS |
|---|---|
| frr | — |
| quagga | Needs evaluation |
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()
1 affected package
assimp
| Package | 16.04 LTS |
|---|---|
| assimp | Needs evaluation |
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components
1 affected package
assimp
| Package | 16.04 LTS |
|---|---|
| assimp | Needs evaluation |
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()
1 affected package
assimp
| Package | 16.04 LTS |
|---|---|
| assimp | Needs evaluation |