Search CVE reports
1741 – 1750 of 43788 results
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a...
2 affected packages
golang-github-go-git-go-git, golang-github-go-git-go-git-v6
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
| golang-github-go-git-go-git-v6 | Not in release |
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining...
2 affected packages
golang-github-go-git-go-git, golang-github-go-git-go-git-v6
| Package | 24.04 LTS |
|---|---|
| golang-github-go-git-go-git | Needs evaluation |
| golang-github-go-git-go-git-v6 | Not in release |
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files...
1 affected package
clamav
| Package | 24.04 LTS |
|---|---|
| clamav | Needs evaluation |
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream...
2 affected packages
smarty3, smarty4
| Package | 24.04 LTS |
|---|---|
| smarty3 | Needs evaluation |
| smarty4 | Needs evaluation |