Search CVE reports
81 – 90 of 35813 results
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes...
2 affected packages
libjwt, libjwt3
| Package | 24.04 LTS |
|---|---|
| libjwt | Needs evaluation |
| libjwt3 | Not in release |
Not in release
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0]...
1 affected package
gitsign
| Package | 24.04 LTS |
|---|---|
| gitsign | Not in release |
Not in release
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before...
1 affected package
gitsign
| Package | 24.04 LTS |
|---|---|
| gitsign | Not in release |
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing...
1 affected package
vorbis-tools
| Package | 24.04 LTS |
|---|---|
| vorbis-tools | Needs evaluation |
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the...
1 affected package
libapache-session-browseable-perl
| Package | 24.04 LTS |
|---|---|
| libapache-session-browseable-perl | Needs evaluation |
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
1 affected package
xen
| Package | 24.04 LTS |
|---|---|
| xen | Needs evaluation |
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
1 affected package
php-mongodb
| Package | 24.04 LTS |
|---|---|
| php-mongodb | Needs evaluation |
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target =...
1 affected package
rust-openssl
| Package | 24.04 LTS |
|---|---|
| rust-openssl | Needs evaluation |
Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium...
1 affected package
chromium-browser
| Package | 24.04 LTS |
|---|---|
| chromium-browser | Not affected |
Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
1 affected package
chromium-browser
| Package | 24.04 LTS |
|---|---|
| chromium-browser | Not affected |