Search CVE reports
471 – 480 of 59380 results
(sprintf-js through 1.1.3 passes unbounded precision specifiers to toFi ...)
1 affected package
node-sprintf-js
| Package | 16.04 LTS |
|---|---|
| node-sprintf-js | Needs evaluation |
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library...
1 affected package
librsvg
| Package | 16.04 LTS |
|---|---|
| librsvg | Needs evaluation |
(An integer overflow in the BSON document encoding component of the Mon ...)
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
(PyMongo's connection string parsing decodes percent-encoded characters ...)
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
(The client-side field level encryption support in the MongoDB Python D ...)
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
(An out-of-bounds write in the connection-monitoring logic of the Mongo ...)
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
(Deserialization of untrusted data in the command monitoring support of ...)
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse...
1 affected package
alsa-lib
| Package | 16.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |
alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size...
1 affected package
alsa-lib
| Package | 16.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |
FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing...
2 affected packages
ffmpeg, libav
| Package | 16.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |