Search CVE reports
41 – 50 of 31565 results
Not in release
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more...
2 affected packages
ffmpeg, libav
| Package | 26.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | Not in release |