Search CVE reports
821 – 830 of 46705 results
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...
1 affected package
keepass2
| Package | 24.04 LTS |
|---|---|
| keepass2 | Needs evaluation |
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching...
1 affected package
bubblewrap
| Package | 24.04 LTS |
|---|---|
| bubblewrap | Vulnerable |
An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.
1 affected package
ocaml-mirage-crypto
| Package | 24.04 LTS |
|---|---|
| ocaml-mirage-crypto | Needs evaluation |
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
1 affected package
ocaml-mirage-crypto
| Package | 24.04 LTS |
|---|---|
| ocaml-mirage-crypto | Needs evaluation |
An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.
1 affected package
ocaml-mirage-crypto
| Package | 24.04 LTS |
|---|---|
| ocaml-mirage-crypto | Needs evaluation |
An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key,...
1 affected package
ocaml-mirage-crypto
| Package | 24.04 LTS |
|---|---|
| ocaml-mirage-crypto | Needs evaluation |
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and...
1 affected package
ocaml-mirage-crypto
| Package | 24.04 LTS |
|---|---|
| ocaml-mirage-crypto | Needs evaluation |
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
1 affected package
opam
| Package | 24.04 LTS |
|---|---|
| opam | Needs evaluation |
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
1 affected package
tor
| Package | 24.04 LTS |
|---|---|
| tor | Needs evaluation |