Search CVE reports
1091 – 1100 of 28513 results
Not in release
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role...
1 affected package
gitlab
| Package | 26.04 LTS |
|---|---|
| gitlab | Not in release |
Not in release
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of...
1 affected package
gitlab
| Package | 26.04 LTS |
|---|---|
| gitlab | Not in release |
Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted...
1 affected package
botan3
| Package | 26.04 LTS |
|---|---|
| botan3 | Needs evaluation |
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote...
1 affected package
streamlink
| Package | 26.04 LTS |
|---|---|
| streamlink | Needs evaluation |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to...
1 affected package
erlang
| Package | 26.04 LTS |
|---|---|
| erlang | Needs evaluation |
Not in release
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on...
1 affected package
gpac
| Package | 26.04 LTS |
|---|---|
| gpac | Not in release |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target,...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight...
6 affected packages
italc, libvncserver, tightvnc, veyon, vino, x11vnc
| Package | 26.04 LTS |
|---|---|
| italc | Not in release |
| libvncserver | Needs evaluation |
| tightvnc | Needs evaluation |
| veyon | Needs evaluation |
| vino | Not in release |
| x11vnc | Needs evaluation |