Search CVE reports
41 – 50 of 40160 results
U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Not in release |
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS |
|---|---|
| u-boot | Needs evaluation |
| u-boot-nezha | Not in release |
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed...
1 affected package
poppler
| Package | 26.04 LTS |
|---|---|
| poppler | Needs evaluation |
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention...
1 affected package
barman
| Package | 26.04 LTS |
|---|---|
| barman | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with...
1 affected package
python-virtualenv
| Package | 26.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker...
1 affected package
python-virtualenv
| Package | 26.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes...
1 affected package
python-virtualenv
| Package | 26.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted...
1 affected package
python-virtualenv
| Package | 26.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches...
1 affected package
jupyterlab
| Package | 26.04 LTS |
|---|---|
| jupyterlab | Needs evaluation |
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be...
1 affected package
poppler
| Package | 26.04 LTS |
|---|---|
| poppler | Needs evaluation |