Search CVE reports
121 – 130 of 36956 results
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location...
1 affected package
libxml-parser-perl
| Package | 22.04 LTS |
|---|---|
| libxml-parser-perl | Needs evaluation |
XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input...
1 affected package
libxml-parser-perl
| Package | 22.04 LTS |
|---|---|
| libxml-parser-perl | Needs evaluation |
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.
2 affected packages
xpdf, ipe
| Package | 22.04 LTS |
|---|---|
| xpdf | Needs evaluation |
| ipe | Needs evaluation |
Not in release
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled...
1 affected package
python-memray
| Package | 22.04 LTS |
|---|---|
| python-memray | Not in release |
Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise...
1 affected package
ruby-devise
| Package | 22.04 LTS |
|---|---|
| ruby-devise | Needs evaluation |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Vulnerable |
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to write information about how well CRAM files are compressed, a check to see if the...
1 affected package
samtools
| Package | 22.04 LTS |
|---|---|
| samtools | Needs evaluation |
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference...
1 affected package
samtools
| Package | 22.04 LTS |
|---|---|
| samtools | Needs evaluation |
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. When reading data encoded using...
1 affected package
htslib
| Package | 22.04 LTS |
|---|---|
| htslib | Needs evaluation |
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it was possible to trigger...
1 affected package
htslib
| Package | 22.04 LTS |
|---|---|
| htslib | Needs evaluation |