Search CVE reports
1021 – 1030 of 57878 results
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
1 affected package
opam
| Package | 16.04 LTS |
|---|---|
| opam | Needs evaluation |
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |
[Unknown description]
1 affected package
modules
| Package | 16.04 LTS |
|---|---|
| modules | Needs evaluation |
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
1 affected package
dpdk
| Package | 16.04 LTS |
|---|---|
| dpdk | Vulnerable |
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded...
1 affected package
gdk-pixbuf
| Package | 16.04 LTS |
|---|---|
| gdk-pixbuf | Needs evaluation |
A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting...
2 affected packages
ffmpeg, libav
| Package | 16.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather...
1 affected package
libhtml-formhandler-perl
| Package | 16.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup....
1 affected package
libhtml-formhandler-perl
| Package | 16.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label...
1 affected package
libhtml-formhandler-perl
| Package | 16.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string...
1 affected package
libhtml-formhandler-perl
| Package | 16.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |