Search CVE reports
281 – 290 of 48104 results
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values...
2 affected packages
asterisk, pjproject
| Package | 24.04 LTS |
|---|---|
| asterisk | Needs evaluation |
| pjproject | Not in release |
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...
2 affected packages
asterisk, pjproject
| Package | 24.04 LTS |
|---|---|
| asterisk | Needs evaluation |
| pjproject | Not in release |
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed...
1 affected package
c-ares
| Package | 24.04 LTS |
|---|---|
| c-ares | Needs evaluation |
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...
1 affected package
c-ares
| Package | 24.04 LTS |
|---|---|
| c-ares | Needs evaluation |
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never...
1 affected package
python-anyio
| Package | 24.04 LTS |
|---|---|
| python-anyio | Needs evaluation |
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser...
1 affected package
icinga2
| Package | 24.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by...
1 affected package
icinga2
| Package | 24.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker...
1 affected package
icinga2
| Package | 24.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation....
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an...
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |