Search CVE reports
1581 – 1590 of 43643 results
Not in release
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 24.04 LTS |
|---|---|
| consul | Not in release |
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large...
1 affected package
pypdf
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator,...
1 affected package
cryptojs
| Package | 24.04 LTS |
|---|---|
| cryptojs | Needs evaluation |
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into...
1 affected package
ruby-json
| Package | 24.04 LTS |
|---|---|
| ruby-json | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as...
1 affected package
libimager-perl
| Package | 24.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a...
2 affected packages
golang-github-go-git-go-git, golang-github-go-git-go-git-v6
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
| golang-github-go-git-go-git-v6 | Not in release |