Search CVE reports
331 – 340 of 47388 results
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...
1 affected package
php-mongodb
| Package | 20.04 LTS |
|---|---|
| php-mongodb | Needs evaluation |
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 20.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 20.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read]
1 affected package
libheif
| Package | 20.04 LTS |
|---|---|
| libheif | Needs evaluation |
[Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read]
1 affected package
libheif
| Package | 20.04 LTS |
|---|---|
| libheif | Needs evaluation |
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP...
1 affected package
node-ajv
| Package | 20.04 LTS |
|---|---|
| node-ajv | Needs evaluation |