Search CVE reports
1501 – 1510 of 42759 results
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file,...
1 affected package
fuse-overlayfs
| Package | 24.04 LTS |
|---|---|
| fuse-overlayfs | Needs evaluation |
undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the...
1 affected package
node-undici
| Package | 24.04 LTS |
|---|---|
| node-undici | Needs evaluation |
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set...
1 affected package
node-undici
| Package | 24.04 LTS |
|---|---|
| node-undici | Needs evaluation |
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved,...
1 affected package
cjson
| Package | 24.04 LTS |
|---|---|
| cjson | Needs evaluation |
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...
4 affected packages
cjson, iperf3, mapcache, sail-ocaml
| Package | 24.04 LTS |
|---|---|
| cjson | Needs evaluation |
| iperf3 | Needs evaluation |
| mapcache | Needs evaluation |
| sail-ocaml | Not in release |
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing...
1 affected package
cjson
| Package | 24.04 LTS |
|---|---|
| cjson | Needs evaluation |
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from...
1 affected package
node-postcss
| Package | 24.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and...
1 affected package
node-postcss
| Package | 24.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
2 affected packages
open-iscsi, open-isns
| Package | 24.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
| open-isns | Needs evaluation |
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
1 affected package
open-iscsi
| Package | 24.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |