Search CVE reports
111 – 120 of 52752 results
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
2 affected packages
sqlite, sqlite3
| Package | 16.04 LTS |
|---|---|
| sqlite | — |
| sqlite3 | Not affected |
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
2 affected packages
sqlite, sqlite3
| Package | 16.04 LTS |
|---|---|
| sqlite | — |
| sqlite3 | Not affected |
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
1 affected package
openvpn
| Package | 16.04 LTS |
|---|---|
| openvpn | Needs evaluation |
Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution...
1 affected package
libdate-manip-perl
| Package | 16.04 LTS |
|---|---|
| libdate-manip-perl | Needs evaluation |
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character...
1 affected package
libdate-manip-perl
| Package | 16.04 LTS |
|---|---|
| libdate-manip-perl | Needs evaluation |
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 16.04 LTS |
|---|---|
| php5 | — |
| php7.0 | Needs evaluation |
| php7.2 | — |
| php7.4 | — |
| php8.1 | — |
| php8.3 | — |
| php8.5 | — |
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 16.04 LTS |
|---|---|
| php5 | — |
| php7.0 | Needs evaluation |
| php7.2 | — |
| php7.4 | — |
| php8.1 | — |
| php8.3 | — |
| php8.5 | — |
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 16.04 LTS |
|---|---|
| php5 | — |
| php7.0 | Needs evaluation |
| php7.2 | — |
| php7.4 | — |
| php8.1 | — |
| php8.3 | — |
| php8.5 | — |
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in...
1 affected package
imagemagick
| Package | 16.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer...
1 affected package
imagemagick
| Package | 16.04 LTS |
|---|---|
| imagemagick | Needs evaluation |