Search CVE reports
81 – 90 of 58628 results
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument...
1 affected package
poppler
| Package | 16.04 LTS |
|---|---|
| poppler | Needs evaluation |
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or...
1 affected package
libimager-perl
| Package | 16.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a...
1 affected package
libimager-perl
| Package | 16.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
[usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
1 affected package
usbredir
| Package | 16.04 LTS |
|---|---|
| usbredir | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 16.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | — |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 16.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | — |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses...
1 affected package
async-http-client
| Package | 16.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can...
1 affected package
async-http-client
| Package | 16.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the...
1 affected package
async-http-client
| Package | 16.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero...
1 affected package
async-http-client
| Package | 16.04 LTS |
|---|---|
| async-http-client | Needs evaluation |