Search CVE reports
71 – 80 of 36041 results
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...
2 affected packages
rust-gix, rust-gix-validate
| Package | 26.04 LTS |
|---|---|
| rust-gix | Needs evaluation |
| rust-gix-validate | Needs evaluation |
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...
1 affected package
rust-gix
| Package | 26.04 LTS |
|---|---|
| rust-gix | Needs evaluation |
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...
1 affected package
rust-gix
| Package | 26.04 LTS |
|---|---|
| rust-gix | Needs evaluation |
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...
1 affected package
rust-gix-packetline
| Package | 26.04 LTS |
|---|---|
| rust-gix-packetline | Needs evaluation |
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...
1 affected package
rust-gix-credentials
| Package | 26.04 LTS |
|---|---|
| rust-gix-credentials | Needs evaluation |
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization...
4 affected packages
rust-gix, rust-gix-features, rust-gix-worktree, rust-gix-worktree-state
| Package | 26.04 LTS |
|---|---|
| rust-gix | Needs evaluation |
| rust-gix-features | Needs evaluation |
| rust-gix-worktree | Needs evaluation |
| rust-gix-worktree-state | Needs evaluation |
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect...
2 affected packages
rust-gix-transport, rust-gix-url
| Package | 26.04 LTS |
|---|---|
| rust-gix-transport | Needs evaluation |
| rust-gix-url | Needs evaluation |
Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
1 affected package
chromium-browser
| Package | 26.04 LTS |
|---|---|
| chromium-browser | Not affected |
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute...
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent...
1 affected package
gdk-pixbuf
| Package | 26.04 LTS |
|---|---|
| gdk-pixbuf | Needs evaluation |