Search CVE reports
1001 – 1010 of 43788 results
kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit...
1 affected package
kas
| Package | 24.04 LTS |
|---|---|
| kas | Needs evaluation |
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...
1 affected package
golang-golang-x-image
| Package | 24.04 LTS |
|---|---|
| golang-golang-x-image | Needs evaluation |
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...
1 affected package
dnsmasq
| Package | 24.04 LTS |
|---|---|
| dnsmasq | Vulnerable |
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
Not in release
actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can...
1 affected package
rust-actix-http
| Package | 24.04 LTS |
|---|---|
| rust-actix-http | Not in release |
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating...
1 affected package
golang-github-go-chi-chi
| Package | 24.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites...
1 affected package
golang-github-go-chi-chi
| Package | 24.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based...
1 affected package
golang-github-go-chi-chi
| Package | 24.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
Not in release
The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path;...
1 affected package
rust-actix-files
| Package | 24.04 LTS |
|---|---|
| rust-actix-files | Not in release |
Not in release
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a...
1 affected package
rust-actix-files
| Package | 24.04 LTS |
|---|---|
| rust-actix-files | Not in release |