Search CVE reports
1881 – 1890 of 43789 results
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
1 affected package
genetic
| Package | 24.04 LTS |
|---|---|
| genetic | Needs evaluation |
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles...
1 affected package
rpm
| Package | 24.04 LTS |
|---|---|
| rpm | Needs evaluation |
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the...
1 affected package
bolt
| Package | 24.04 LTS |
|---|---|
| bolt | Needs evaluation |
Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like...
1 affected package
cacti
| Package | 24.04 LTS |
|---|---|
| cacti | Needs evaluation |
tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern...
2 affected packages
goxel, raylib
| Package | 24.04 LTS |
|---|---|
| goxel | Needs evaluation |
| raylib | Not in release |
dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to...
3 affected packages
libchdr, qt6-multimedia, qtads
| Package | 24.04 LTS |
|---|---|
| libchdr | Needs evaluation |
| qt6-multimedia | Needs evaluation |
| qtads | Needs evaluation |
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all()...
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses...
1 affected package
libkcapi
| Package | 24.04 LTS |
|---|---|
| libkcapi | Needs evaluation |
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--'...
4 affected packages
ffmpeg, libav, its, yt-dlp
| Package | 24.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
| its | Not in release |
| yt-dlp | Needs evaluation |