Search CVE reports
1071 – 1080 of 52944 results
Not in release
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example,...
1 affected package
rust-rustls-webpki
| Package | 22.04 LTS |
|---|---|
| rust-rustls-webpki | Not in release |
Not in release
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced....
1 affected package
rust-rustls-webpki
| Package | 22.04 LTS |
|---|---|
| rust-rustls-webpki | Not in release |
Not in release
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly...
1 affected package
rust-rustls-webpki
| Package | 22.04 LTS |
|---|---|
| rust-rustls-webpki | Not in release |
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Not affected |
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Vulnerable |
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Vulnerable |
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Vulnerable |
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability...
1 affected package
imagemagick
| Package | 22.04 LTS |
|---|---|
| imagemagick | Vulnerable |
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or...
1 affected package
libimager-perl
| Package | 22.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |