Search CVE reports
1321 – 1330 of 43788 results
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
1 affected package
rlottie
| Package | 24.04 LTS |
|---|---|
| rlottie | Needs evaluation |
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not affected |
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Fixed |
| dotnet9 | Not in release |
| dotnet10 | Fixed |
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not affected |
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Fixed |
| dotnet9 | Not in release |
| dotnet10 | Fixed |
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Fixed |
| dotnet9 | Not in release |
| dotnet10 | Fixed |
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Fixed |
| dotnet9 | Not in release |
| dotnet10 | Fixed |
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not affected |
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not affected |
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not affected |