Search CVE reports
461 – 470 of 37500 results
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...
12 affected packages
pypy3, python2.7, python3.4, python3.5, python3.6...
| Package | 26.04 LTS |
|---|---|
| pypy3 | Needs evaluation |
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Not in release |
| python3.14 | Needs evaluation |
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...
1 affected package
node-multiparty
| Package | 26.04 LTS |
|---|---|
| node-multiparty | Needs evaluation |
morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that...
1 affected package
node-morgan
| Package | 26.04 LTS |
|---|---|
| node-morgan | Needs evaluation |
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...
1 affected package
node-compression
| Package | 26.04 LTS |
|---|---|
| node-compression | Needs evaluation |
Not in release
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
1 affected package
orthanc
| Package | 26.04 LTS |
|---|---|
| orthanc | Needs evaluation |
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...
1 affected package
keepass2
| Package | 26.04 LTS |
|---|---|
| keepass2 | Needs evaluation |
Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell...
1 affected package
puppetserver
| Package | 26.04 LTS |
|---|---|
| puppetserver | Needs evaluation |
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...
1 affected package
libfreemarker-java
| Package | 26.04 LTS |
|---|---|
| libfreemarker-java | Needs evaluation |
A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit...
1 affected package
golang-github-google-cel-go
| Package | 26.04 LTS |
|---|---|
| golang-github-google-cel-go | Needs evaluation |