Search CVE reports
691 – 700 of 50807 results
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
1 affected package
live-boot
| Package | 22.04 LTS |
|---|---|
| live-boot | Needs evaluation |
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...
2 affected packages
glibc, eglibc
| Package | 22.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds...
1 affected package
gst-plugins-good1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling...
1 affected package
mruby
| Package | 22.04 LTS |
|---|---|
| mruby | Needs evaluation |