Search CVE reports
1301 – 1310 of 47890 results
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before...
1 affected package
vim
| Package | 22.04 LTS |
|---|---|
| vim | Vulnerable |
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer,...
1 affected package
vim
| Package | 22.04 LTS |
|---|---|
| vim | Vulnerable |
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures...
1 affected package
vim
| Package | 22.04 LTS |
|---|---|
| vim | Not affected |
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could...
1 affected package
libtpms
| Package | 22.04 LTS |
|---|---|
| libtpms | Needs evaluation |
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an...
1 affected package
libtpms
| Package | 22.04 LTS |
|---|---|
| libtpms | Needs evaluation |
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original...
1 affected package
libdbi-perl
| Package | 22.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run,...
1 affected package
tesseract
| Package | 22.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in...
1 affected package
tesseract
| Package | 22.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 22.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not affected |
| freerdp3 | Not in release |