Search CVE reports
801 – 810 of 46705 results
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content...
1 affected package
fastdds
| Package | 24.04 LTS |
|---|---|
| fastdds | Needs evaluation |
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds...
1 affected package
fastdds
| Package | 24.04 LTS |
|---|---|
| fastdds | Needs evaluation |
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset...
1 affected package
zstd-jni-java
| Package | 24.04 LTS |
|---|---|
| zstd-jni-java | Needs evaluation |
t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized...
1 affected package
t-digest
| Package | 24.04 LTS |
|---|---|
| t-digest | Needs evaluation |
A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit...
1 affected package
golang-github-google-cel-go
| Package | 24.04 LTS |
|---|---|
| golang-github-google-cel-go | Needs evaluation |
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may...
1 affected package
vlc
| Package | 24.04 LTS |
|---|---|
| vlc | Needs evaluation |
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with...
1 affected package
vlc
| Package | 24.04 LTS |
|---|---|
| vlc | Needs evaluation |