Search CVE reports
1171 – 1180 of 37432 results
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
1 affected package
freeipmi
| Package | 26.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031...
1 affected package
freeipmi
| Package | 26.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
1 affected package
freeipmi
| Package | 26.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
2 affected packages
xpdf, ipe
| Package | 26.04 LTS |
|---|---|
| xpdf | Needs evaluation |
| ipe | Needs evaluation |
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries...
1 affected package
ruby-zip
| Package | 26.04 LTS |
|---|---|
| ruby-zip | Needs evaluation |
Not in release
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens...
1 affected package
python-jose
| Package | 26.04 LTS |
|---|---|
| python-jose | Not in release |
Not in release
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid...
1 affected package
node-node-forge
| Package | 26.04 LTS |
|---|---|
| node-node-forge | Not in release |
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace...
1 affected package
gst-plugins-base1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-base1.0 | Vulnerable |
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow...
4 affected packages
zlib, rsync, klibc, zsync
| Package | 26.04 LTS |
|---|---|
| zlib | Vulnerable |
| rsync | Not affected |
| klibc | Vulnerable |
| zsync | Vulnerable |
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 26.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not in release |
| freerdp3 | Fixed |