Search CVE reports
11 – 20 of 39239 results
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in usual mode with create_id enabled, Oj::Parser#parse is vulnerable to heap corruption via a negative-size...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling symbol_keys on a reused Oj::Parser instance triggers a heap use-after-free. When symbol_keys is toggled from...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parser#parse is vulnerable to a heap use-after-free when a SAJ/SAJ2 callback mutates the input JSON string during...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (each_value, each_child, each_leaf) were vulnerable to a heap use-after-free. When a Ruby block yielded during...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in object mode, Oj.dump is vulnerable to a heap buffer overflow when serializing Exception objects with a large...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#each_child, when invoked recursively over a deeply nested JSON document, overflows a fixed-size stack buffer...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer....
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON...
1 affected package
ruby-oj
| Package | 24.04 LTS |
|---|---|
| ruby-oj | Needs evaluation |
[LogFormatter: 'raw' parameter format is no longer raw HTML]
1 affected package
mediawiki
| Package | 24.04 LTS |
|---|---|
| mediawiki | Needs evaluation |
[Fix ApiQueryUsers leaking status ofprivate user conditions for user]
1 affected package
mediawiki
| Package | 24.04 LTS |
|---|---|
| mediawiki | Needs evaluation |