Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2024-53984

Medium priority
Needs evaluation

Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, the message contains at least one field with FT_POINTER field type, custom stream callback is used with...

1 affected packages

nanopb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nanopb Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-5742

Low priority

Some fixes available 6 of 7

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user...

1 affected packages

nano

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nano Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2014-125106

Medium priority
Not affected

Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.

1 affected packages

nanopb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nanopb Not affected Not affected Ignored Ignored
Show less packages

CVE-2022-20203

Medium priority
Needs evaluation

In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User...

1 affected packages

nanopb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nanopb Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-21401

Medium priority

Some fixes available 1 of 4

Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message...

1 affected packages

nanopb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nanopb Not affected Not affected Fixed Not in release Not in release
Show less packages

CVE-2020-26243

Medium priority

Some fixes available 1 of 2

Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static...

1 affected packages

nanopb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nanopb Not affected Not affected Fixed Not in release Not in release
Show less packages

CVE-2010-1161

Low priority
Ignored

Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.

1 affected packages

nano

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nano
Show less packages

CVE-2010-1160

Low priority
Ignored

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an...

1 affected packages

nano

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nano
Show less packages

CVE-2003-0453

Unknown priority
Fixed

1 affected packages

traceroute-nanog

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
traceroute-nanog
Show less packages