Search CVE reports
1281 – 1290 of 43788 results
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment()...
1 affected package
coturn
| Package | 24.04 LTS |
|---|---|
| coturn | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(),...
1 affected package
coturn
| Package | 24.04 LTS |
|---|---|
| coturn | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible,...
1 affected package
coturn
| Package | 24.04 LTS |
|---|---|
| coturn | Needs evaluation |
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces...
1 affected package
nmap
| Package | 24.04 LTS |
|---|---|
| nmap | Needs evaluation |
Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in...
1 affected package
node-browserslist
| Package | 24.04 LTS |
|---|---|
| node-browserslist | Needs evaluation |
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every...
1 affected package
node-browserslist
| Package | 24.04 LTS |
|---|---|
| node-browserslist | Needs evaluation |
Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |