Security
Headlines
HeadlinesLatestCVEs

Tag

#dos

CVE-2021-45340: NULL pointer dereference in stb_image.h · Issue #51 · libsixel/libsixel

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVE
#dos
RHSA-2022:0246: Red Hat Security Advisory: nodejs:14 security, bug fix, and enhancement update

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2020-7788: nodejs-ini: Prototype pollution via malicious INI file * CVE-2020-28469: nodejs-glob-parent: Regular expression denial of service * CVE-2021-3807: nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes * CVE-2021-3918: nodejs-json-schema: Prototype pollution vulnerability *...

CVE-2021-46480: Heap-buffer-overflow src/jsiEval.c:464 in jsiValueObjDelete · Issue #61 · pcmacdon/jsish

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46477: Heap-buffer-overflow src/jsiRegexp.c:176 in RegExp_constructor · Issue #63 · pcmacdon/jsish

Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46475: Heap-buffer-overflow src/jsiArray.c:912 in jsi_ArraySliceCmd · Issue #64 · pcmacdon/jsish

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46478: Heap-buffer-overflow src/jsiEval.c:120 in jsiClearStack · Issue #60 · pcmacdon/jsish

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46474: Heap-buffer-overflow src/jsiEval.c:1366 in jsiEvalCodeSub · Issue #57 · pcmacdon/jsish

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-36349: DSA-2021-262: Dell EMC Data Protection Central Security Update for Multiple Security Vulnerabilities

Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.

CVE-2022-21708: Denial of Service caused by a bug in the MaxDepth schema option

graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overflow panics. Any user with access to the GraphQL handler can send these queries and cause stack overflows. This in turn could potentially compromise the ability of the server to serve data to its users. The issue has been patched in version `v1.3.0`. The only known workaround for this issue is to disable the `graphql.MaxDepth` option from your schema which is not recommended.

CVE-2021-39480: memory allocation of 18446744073709551610 bytes failed[1] · Issue #30 · m4b/bingrep

Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).