Total vulnerabilities in the database
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Software | From | Fixed in |
---|---|---|
oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
oracle / communications_cloud_native_core_policy | 1.14.0 | 1.14.0.x |
splunk / universal_forwarder | 9.1.0 | 9.1.0.x |
splunk / universal_forwarder | 9.0.0 | 9.0.6 |
splunk / universal_forwarder | 8.2.0 | 8.2.12 |
lz4_project / lz4 | 1.8.3 | 1.9.4 |