Search CVE reports
1731 – 1740 of 43788 results
Not in release
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large...
1 affected package
pypdf
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator,...
1 affected package
cryptojs
| Package | 24.04 LTS |
|---|---|
| cryptojs | Needs evaluation |
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into...
1 affected package
ruby-json
| Package | 24.04 LTS |
|---|---|
| ruby-json | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as...
1 affected package
libimager-perl
| Package | 24.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |