Search CVE reports
481 – 490 of 45567 results
A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The...
1 affected package
flvmeta
| Package | 24.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow....
1 affected package
flvmeta
| Package | 24.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to...
1 affected package
liburi-perl
| Package | 24.04 LTS |
|---|---|
| liburi-perl | Needs evaluation |
Not in release
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed...
1 affected package
rust-zbus-polkit
| Package | 24.04 LTS |
|---|---|
| rust-zbus-polkit | Not in release |
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak...
1 affected package
wordpress
| Package | 24.04 LTS |
|---|---|
| wordpress | Needs evaluation |
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
1 affected package
rlottie
| Package | 24.04 LTS |
|---|---|
| rlottie | Needs evaluation |
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(),...
1 affected package
node-nodemailer
| Package | 24.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage...
1 affected package
node-nodemailer
| Package | 24.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can...
1 affected package
node-nodemailer
| Package | 24.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject...
1 affected package
node-nodemailer
| Package | 24.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |