Search CVE reports
1161 – 1170 of 47788 results
Not in release
[MQTT v5 properties bounds check uses relative offset against absolute position]
1 affected package
mongoose
| Package | 22.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
[w5100_rx wraparound RX path copies n instead of r bytes]
1 affected package
mongoose
| Package | 22.04 LTS |
|---|---|
| mongoose | Not in release |
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI...
1 affected package
flawfinder
| Package | 22.04 LTS |
|---|---|
| flawfinder | Needs evaluation |
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked...
1 affected package
python-engineio
| Package | 22.04 LTS |
|---|---|
| python-engineio | Needs evaluation |
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the...
1 affected package
python-socketio
| Package | 22.04 LTS |
|---|---|
| python-socketio | Needs evaluation |
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the...
1 affected package
python-engineio
| Package | 22.04 LTS |
|---|---|
| python-engineio | Needs evaluation |
Not in release
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this...
1 affected package
golang-github-sigstore-sigstore
| Package | 22.04 LTS |
|---|---|
| golang-github-sigstore-sigstore | Not in release |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...
1 affected package
nagios4
| Package | 22.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...
1 affected package
nagios4
| Package | 22.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...
1 affected package
nagios4
| Package | 22.04 LTS |
|---|---|
| nagios4 | Needs evaluation |