Search CVE reports
161 – 170 of 44746 results
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19,...
12 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 22.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | Not in release |
| openjdk-lts | Needs evaluation |
| openjdk-13 | Not in release |
| openjdk-16 | Not in release |
| openjdk-17 | Needs evaluation |
| openjdk-17-crac | Not in release |
| openjdk-18 | Ignored |
| openjdk-21 | Needs evaluation |
| openjdk-21-crac | Not in release |
| openjdk-25 | Needs evaluation |
| openjdk-26 | Not in release |
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled...
1 affected package
capstone
| Package | 22.04 LTS |
|---|---|
| capstone | Needs evaluation |
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
1 affected package
golang-golang-x-text
| Package | 22.04 LTS |
|---|---|
| golang-golang-x-text | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to...
1 affected package
cimg
| Package | 22.04 LTS |
|---|---|
| cimg | Needs evaluation |
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
1 affected package
golang-1.23
| Package | 22.04 LTS |
|---|---|
| golang-1.23 | Needs evaluation |
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when...
2 affected packages
ansible, ansible-core
| Package | 22.04 LTS |
|---|---|
| ansible | Needs evaluation |
| ansible-core | Needs evaluation |
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
2 affected packages
docker.io, docker.io-app
| Package | 22.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
2 affected packages
docker.io, docker.io-app
| Package | 22.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host...
2 affected packages
docker.io, docker.io-app
| Package | 22.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients...
1 affected package
libssh
| Package | 22.04 LTS |
|---|---|
| libssh | Needs evaluation |