Search CVE reports
31 – 40 of 36262 results
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...
1 affected package
php-mongodb
| Package | 26.04 LTS |
|---|---|
| php-mongodb | Needs evaluation |
Not in release
An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field...
1 affected package
mongo-cxx-driver
| Package | 26.04 LTS |
|---|---|
| mongo-cxx-driver | Not in release |
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...
1 affected package
mongo-c-driver
| Package | 26.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key...
1 affected package
libmongocrypt
| Package | 26.04 LTS |
|---|---|
| libmongocrypt | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 26.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Unknown description]
1 affected package
openvpn
| Package | 26.04 LTS |
|---|---|
| openvpn | Needs evaluation |
[Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read]
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |