Search CVE reports
1 – 10 of 35993 results
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be...
1 affected package
valkey
| Package | 26.04 LTS |
|---|---|
| valkey | Needs evaluation |
A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in...
1 affected package
valkey
| Package | 26.04 LTS |
|---|---|
| valkey | Needs evaluation |
A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History...
1 affected package
open62541
| Package | 26.04 LTS |
|---|---|
| open62541 | Needs evaluation |
A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to...
1 affected package
kamailio
| Package | 26.04 LTS |
|---|---|
| kamailio | Needs evaluation |
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the...
1 affected package
assimp
| Package | 26.04 LTS |
|---|---|
| assimp | Needs evaluation |
### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while...
1 affected package
node-qs
| Package | 26.04 LTS |
|---|---|
| node-qs | Needs evaluation |
The cohttp package before 6.3.0 for OCaml allows directory traversal.
1 affected package
ocaml-cohttp
| Package | 26.04 LTS |
|---|---|
| ocaml-cohttp | Needs evaluation |
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...
1 affected package
sudo
| Package | 26.04 LTS |
|---|---|
| sudo | Needs evaluation |
Not in release
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |
Not in release
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via...
1 affected package
ruby-rodauth
| Package | 26.04 LTS |
|---|---|
| ruby-rodauth | Not in release |