Search CVE reports
211 – 220 of 37368 results
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace,...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
Not in release
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a...
1 affected package
nats-server
| Package | 22.04 LTS |
|---|---|
| nats-server | Not in release |
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
1 affected package
osslsigncode
| Package | 22.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper...
2 affected packages
libpf4j-java, libpf4j-update-java
| Package | 22.04 LTS |
|---|---|
| libpf4j-java | Needs evaluation |
| libpf4j-update-java | Needs evaluation |
Not in release
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
1 affected package
plexus-utils
| Package | 22.04 LTS |
|---|---|
| plexus-utils | Not in release |
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
1 affected package
fontconfig
| Package | 22.04 LTS |
|---|---|
| fontconfig | Not affected |