Search CVE reports
1581 – 1590 of 38021 results
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
1 affected package
libxml2
| Package | 26.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
1 affected package
libxml2
| Package | 26.04 LTS |
|---|---|
| libxml2 | Vulnerable |
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
1 affected package
libxml2
| Package | 26.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
1 affected package
libxml2
| Package | 26.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
1 affected package
libxml2
| Package | 26.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying...
1 affected package
ndpi
| Package | 26.04 LTS |
|---|---|
| ndpi | Needs evaluation |
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS |
|---|---|
| netcdf | Needs evaluation |
| netcdf-parallel | Needs evaluation |
Not in release
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete...
1 affected package
ntopng
| Package | 26.04 LTS |
|---|---|
| ntopng | Not in release |
Not in release
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured...
1 affected package
ntopng
| Package | 26.04 LTS |
|---|---|
| ntopng | Not in release |
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before...
1 affected package
flatpak
| Package | 26.04 LTS |
|---|---|
| flatpak | Needs evaluation |