Search CVE reports
531 – 540 of 36488 results
[Unknown description]
2 affected packages
qemu, qemu-hwe
| Package | 26.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | Needs evaluation |
[Unknown description]
2 affected packages
qemu, qemu-hwe
| Package | 26.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | Needs evaluation |
[Unknown description]
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Not in release |
[Unknown description]
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Not in release |
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the...
1 affected package
assimp
| Package | 26.04 LTS |
|---|---|
| assimp | Needs evaluation |
### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while...
1 affected package
node-qs
| Package | 26.04 LTS |
|---|---|
| node-qs | Needs evaluation |
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by...
1 affected package
node-qs
| Package | 26.04 LTS |
|---|---|
| node-qs | Needs evaluation |
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...
1 affected package
sudo
| Package | 26.04 LTS |
|---|---|
| sudo | Needs evaluation |
Not in release
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |