Search CVE reports
141 – 150 of 38451 results
A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A...
1 affected package
orthanc
| Package | 20.04 LTS |
|---|---|
| orthanc | Needs evaluation |
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An...
1 affected package
orthanc
| Package | 20.04 LTS |
|---|---|
| orthanc | Needs evaluation |
A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on...
1 affected package
orthanc
| Package | 20.04 LTS |
|---|---|
| orthanc | Needs evaluation |
An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although...
1 affected package
orthanc
| Package | 20.04 LTS |
|---|---|
| orthanc | Needs evaluation |
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a...
1 affected package
node-axios
| Package | 20.04 LTS |
|---|---|
| node-axios | Needs evaluation |
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack...
1 affected package
sleuthkit
| Package | 20.04 LTS |
|---|---|
| sleuthkit | Needs evaluation |
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap...
1 affected package
sleuthkit
| Package | 20.04 LTS |
|---|---|
| sleuthkit | Needs evaluation |
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent...
1 affected package
node-axios
| Package | 20.04 LTS |
|---|---|
| node-axios | Needs evaluation |