Search CVE reports
661 – 670 of 33680 results
Not in release
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.
1 affected package
grafana
| Package | 26.04 LTS |
|---|---|
| grafana | Not in release |
An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 26.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Not in release |
| emacs25 | Not in release |
GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 26.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Not in release |
| emacs25 | Not in release |
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 26.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Not in release |
| emacs25 | Not in release |
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 26.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Not in release |
| emacs25 | Not in release |
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An...
1 affected package
cpio
| Package | 26.04 LTS |
|---|---|
| cpio | Needs evaluation |
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled...
1 affected package
cpio
| Package | 26.04 LTS |
|---|---|
| cpio | Needs evaluation |
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar...
1 affected package
cpio
| Package | 26.04 LTS |
|---|---|
| cpio | Needs evaluation |
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |