Search CVE reports
1011 – 1020 of 52944 results
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in...
1 affected package
node-deepmerge
| Package | 22.04 LTS |
|---|---|
| node-deepmerge | Needs evaluation |
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...
1 affected package
node-uri-js
| Package | 22.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...
1 affected package
node-got
| Package | 22.04 LTS |
|---|---|
| node-got | Needs evaluation |
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...
1 affected package
node-postcss
| Package | 22.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....
1 affected package
node-got
| Package | 22.04 LTS |
|---|---|
| node-got | Needs evaluation |
A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword`...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values...
2 affected packages
asterisk, pjproject
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
| pjproject | Not in release |
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...
2 affected packages
asterisk, pjproject
| Package | 22.04 LTS |
|---|---|
| asterisk | Needs evaluation |
| pjproject | Not in release |