Search CVE reports
2041 – 2050 of 38256 results
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key...
1 affected package
libmongocrypt
| Package | 26.04 LTS |
|---|---|
| libmongocrypt | Needs evaluation |
Not in release
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...
1 affected package
ntopng
| Package | 26.04 LTS |
|---|---|
| ntopng | Not in release |
Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed...
1 affected package
libmongocrypt
| Package | 26.04 LTS |
|---|---|
| libmongocrypt | Needs evaluation |
Not in release
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when...
1 affected package
mongo-cxx-driver
| Package | 26.04 LTS |
|---|---|
| mongo-cxx-driver | Not in release |
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace...
1 affected package
gst-plugins-base1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-base1.0 | Vulnerable |
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow...
4 affected packages
zlib, rsync, klibc, zsync
| Package | 26.04 LTS |
|---|---|
| zlib | Vulnerable |
| rsync | Not affected |
| klibc | Vulnerable |
| zsync | Vulnerable |
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 26.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Not in release |
| freerdp3 | Fixed |