Search CVE reports
431 – 440 of 27850 results
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote...
1 affected package
streamlink
| Package | 26.04 LTS |
|---|---|
| streamlink | Needs evaluation |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to...
1 affected package
erlang
| Package | 26.04 LTS |
|---|---|
| erlang | Needs evaluation |
Not in release
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on...
1 affected package
gpac
| Package | 26.04 LTS |
|---|---|
| gpac | Not in release |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target,...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous...
1 affected package
golang-github-go-git-go-git
| Package | 26.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight...
6 affected packages
libvncserver, vino, x11vnc, veyon, italc, tightvnc
| Package | 26.04 LTS |
|---|---|
| libvncserver | Needs evaluation |
| vino | Not in release |
| x11vnc | Needs evaluation |
| veyon | Needs evaluation |
| italc | Not in release |
| tightvnc | Needs evaluation |
Not in release
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
1 affected package
broker
| Package | 26.04 LTS |
|---|---|
| broker | Not in release |
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as...
1 affected package
rabbitmq-server
| Package | 26.04 LTS |
|---|---|
| rabbitmq-server | Not affected |
Not in release
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.
1 affected package
dolibarr
| Package | 26.04 LTS |
|---|---|
| dolibarr | Not in release |