Search CVE reports
1 – 10 of 18 results
Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
1 affected package
nanomsg
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nanomsg | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
1 affected package
nanosvg
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nanosvg | Needs evaluation | Needs evaluation | Not in release | — | — |
(NanoSVG 239e102ec contains an incorrect numeric conversion vulnerabili ...)
1 affected package
nanosvg
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nanosvg | Needs evaluation | Needs evaluation | Not in release | — | — |
(NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
1 affected package
nanosvg
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nanosvg | Needs evaluation | Needs evaluation | Not in release | — | — |
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
1 affected package
libnanoxml2-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libnanoxml2-java | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can...
1 affected package
nano
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nano | Fixed | Fixed | Fixed | Not affected | Not affected |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
1 affected package
nano
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nano | Not affected | Not affected | Not affected | Not affected | Not affected |
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name,...
1 affected package
nano
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nano | Fixed | Fixed | Fixed | Not affected | Not affected |
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject...
1 affected package
nano
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nano | Fixed | Fixed | Fixed | Fixed | Fixed |
Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, the message contains at least one field with FT_POINTER field type, custom stream callback is used with...
1 affected package
nanopb
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nanopb | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |