Search CVE reports
691 – 700 of 48476 results
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and...
1 affected package
xdg-dbus-proxy
| Package | 24.04 LTS |
|---|---|
| xdg-dbus-proxy | Needs evaluation |
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership...
1 affected package
rust-coreutils
| Package | 24.04 LTS |
|---|---|
| rust-coreutils | Needs evaluation |
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results....
1 affected package
rust-hickory-resolver
| Package | 24.04 LTS |
|---|---|
| rust-hickory-resolver | Needs evaluation |
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count...
1 affected package
poppler
| Package | 24.04 LTS |
|---|---|
| poppler | Needs evaluation |
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |