Search CVE reports
1811 – 1820 of 51437 results
ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the...
1 affected package
ugrep
| Package | 22.04 LTS |
|---|---|
| ugrep | Needs evaluation |
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does...
1 affected package
pcre2
| Package | 22.04 LTS |
|---|---|
| pcre2 | Needs evaluation |
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader...
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has...
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Vulnerable |
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
1 affected package
libxml2
| Package | 22.04 LTS |
|---|---|
| libxml2 | Needs evaluation |