Search CVE reports
821 – 830 of 44358 results
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its...
1 affected package
apache-opennlp
| Package | 20.04 LTS |
|---|---|
| apache-opennlp | Needs evaluation |
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap...
1 affected package
coreutils
| Package | 20.04 LTS |
|---|---|
| coreutils | Needs evaluation |
GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly...
1 affected package
coreutils
| Package | 20.04 LTS |
|---|---|
| coreutils | Needs evaluation |
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
1 affected package
zaqar
| Package | 20.04 LTS |
|---|---|
| zaqar | Needs evaluation |
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval,...
1 affected package
knot
| Package | 20.04 LTS |
|---|---|
| knot | Needs evaluation |
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The...
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph...
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function...
2 affected packages
ffmpeg, libav
| Package | 20.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |