Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2021-44510

Low priority

Some fixes available 4 of 8

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an...

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-44509

Medium priority

Some fixes available 4 of 8

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to...

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-44508

Medium priority

Some fixes available 4 of 8

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-44507

Low priority
Ignored

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Ignored Ignored Not affected Not affected
Show less packages

CVE-2021-44506

Low priority

Some fixes available 4 of 8

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a...

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-44505

Medium priority
Ignored

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-44504

Low priority
Ignored

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted...

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-44503

Medium priority
Ignored

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-44502

Medium priority

Some fixes available 4 of 8

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-44501

Medium priority
Ignored

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

1 affected package

fis-gtm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fis-gtm Not affected Ignored Ignored Ignored Ignored
Show less packages