Search CVE reports
1001 – 1010 of 52944 results
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its...
1 affected package
fluidsynth
| Package | 22.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the...
1 affected package
fluidsynth
| Package | 22.04 LTS |
|---|---|
| fluidsynth | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe...
1 affected package
suricata
| Package | 22.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions...
1 affected package
suricata
| Package | 22.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash...
1 affected package
suricata
| Package | 22.04 LTS |
|---|---|
| suricata | Needs evaluation |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...
1 affected package
blazar
| Package | 22.04 LTS |
|---|---|
| blazar | Not in release |
Not in release
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...
1 affected package
blazar
| Package | 22.04 LTS |
|---|---|
| blazar | Not in release |
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.
1 affected package
osmo-iuh
| Package | 22.04 LTS |
|---|---|
| osmo-iuh | Needs evaluation |
In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths.
1 affected package
osmo-bsc
| Package | 22.04 LTS |
|---|---|
| osmo-bsc | Needs evaluation |
In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.
1 affected package
osmo-ggsn
| Package | 22.04 LTS |
|---|---|
| osmo-ggsn | Needs evaluation |