Search CVE reports
1 – 10 of 50126 results
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
1 affected package
r-cran-readxl
| Package | 22.04 LTS |
|---|---|
| r-cran-readxl | Needs evaluation |
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
1 affected package
r-cran-readxl
| Package | 22.04 LTS |
|---|---|
| r-cran-readxl | Needs evaluation |
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling...
1 affected package
mruby
| Package | 22.04 LTS |
|---|---|
| mruby | Needs evaluation |
An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.
1 affected package
libstb
| Package | 22.04 LTS |
|---|---|
| libstb | Needs evaluation |
An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.
1 affected package
libstb
| Package | 22.04 LTS |
|---|---|
| libstb | Needs evaluation |
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
1 affected package
wpa
| Package | 22.04 LTS |
|---|---|
| wpa | Needs evaluation |
[Unknown description]
1 affected package
libdbi-perl
| Package | 22.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...
2 affected packages
libvirt, libvirt-hwe
| Package | 22.04 LTS |
|---|---|
| libvirt | Needs evaluation |
| libvirt-hwe | Not in release |
SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256...
1 affected package
spip
| Package | 22.04 LTS |
|---|---|
| spip | Needs evaluation |