Search CVE reports
451 – 460 of 35883 results
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
1 affected package
gpac
| Package | 22.04 LTS |
|---|---|
| gpac | Needs evaluation |
Not in release
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
Not in release
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Fixed |
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Fixed |
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Fixed |
Not in release
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion...
1 affected package
keras
| Package | 22.04 LTS |
|---|---|
| keras | Not in release |
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
1 affected package
wireshark
| Package | 22.04 LTS |
|---|---|
| wireshark | Needs evaluation |
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
1 affected package
wireshark
| Package | 22.04 LTS |
|---|---|
| wireshark | Needs evaluation |
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
1 affected package
wireshark
| Package | 22.04 LTS |
|---|---|
| wireshark | Needs evaluation |