Search CVE reports
1 – 10 of 58662 results
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths...
1 affected package
jackson-databind
| Package | 16.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for...
1 affected package
jackson-databind
| Package | 16.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the...
1 affected package
jackson-core
| Package | 16.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
[Unknown description]
1 affected package
zbar
| Package | 16.04 LTS |
|---|---|
| zbar | Needs evaluation |
[Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
[mdtls discards the peer-identity verification result]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
[Unknown description]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().
1 affected package
mpack
| Package | 16.04 LTS |
|---|---|
| mpack | Needs evaluation |
A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion...
1 affected package
yara
| Package | 16.04 LTS |
|---|---|
| yara | Needs evaluation |