Search CVE reports
151 – 160 of 46300 results
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...
1 affected package
consul
| Package | 22.04 LTS |
|---|---|
| consul | Needs evaluation |
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A...
1 affected package
gst-plugins-good1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...
1 affected package
libstb
| Package | 22.04 LTS |
|---|---|
| libstb | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 22.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 22.04 LTS |
|---|---|
| consul | Needs evaluation |
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...
1 affected package
dracut
| Package | 22.04 LTS |
|---|---|
| dracut | Needs evaluation |
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...
1 affected package
bouncycastle
| Package | 22.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
local privilege escalation via missing home-record signature verification on the authenticate path
1 affected package
systemd
| Package | 22.04 LTS |
|---|---|
| systemd | Fixed |
unprivileged users can terminate arbitrary processes
1 affected package
systemd
| Package | 22.04 LTS |
|---|---|
| systemd | Not affected |
unprivileged users can terminate arbitrary processes
1 affected package
systemd
| Package | 22.04 LTS |
|---|---|
| systemd | Fixed |