Search CVE reports
341 – 350 of 27411 results
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 26.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not in release |
| freerdp3 | Needs evaluation |
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow....
1 affected package
squirrel3
| Package | 26.04 LTS |
|---|---|
| squirrel3 | Needs evaluation |
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in...
1 affected package
perl
| Package | 26.04 LTS |
|---|---|
| perl | Needs evaluation |
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the...
1 affected package
perl
| Package | 26.04 LTS |
|---|---|
| perl | Needs evaluation |
[Stack Buffer Overflow in radvdump Route Information Option Parser]
1 affected package
radvd
| Package | 26.04 LTS |
|---|---|
| radvd | Needs evaluation |
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path...
1 affected package
starlette
| Package | 26.04 LTS |
|---|---|
| starlette | Needs evaluation |
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta...
1 affected package
samba
| Package | 26.04 LTS |
|---|---|
| samba | Fixed |
Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server
1 affected package
samba
| Package | 26.04 LTS |
|---|---|
| samba | Fixed |
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute...
1 affected package
perl
| Package | 26.04 LTS |
|---|---|
| perl | Needs evaluation |
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against...
1 affected package
perl
| Package | 26.04 LTS |
|---|---|
| perl | Needs evaluation |