Search CVE reports
61 – 70 of 42237 results
[Unknown description]
1 affected package
geary
| Package | 20.04 LTS |
|---|---|
| geary | Needs evaluation |
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option...
1 affected package
antlr4
| Package | 20.04 LTS |
|---|---|
| antlr4 | Needs evaluation |
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin....
1 affected package
antlr4
| Package | 20.04 LTS |
|---|---|
| antlr4 | Needs evaluation |
A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The...
1 affected package
antlr4
| Package | 20.04 LTS |
|---|---|
| antlr4 | Needs evaluation |
A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation...
1 affected package
antlr4
| Package | 20.04 LTS |
|---|---|
| antlr4 | Needs evaluation |
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows...
1 affected package
nmap
| Package | 20.04 LTS |
|---|---|
| nmap | Needs evaluation |
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers...
1 affected package
nghttp2
| Package | 20.04 LTS |
|---|---|
| nghttp2 | Needs evaluation |
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on...
1 affected package
libssh2
| Package | 20.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on...
1 affected package
libssh2
| Package | 20.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run...
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |