Search CVE reports
1421 – 1430 of 37432 results
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields....
1 affected package
python-tornado
| Package | 26.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Not in release
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
1 affected package
webkitgtk
| Package | 26.04 LTS |
|---|---|
| webkitgtk | Not in release |
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...
1 affected package
gdb
| Package | 26.04 LTS |
|---|---|
| gdb | Needs evaluation |
A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The...
1 affected package
flvmeta
| Package | 26.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow....
1 affected package
flvmeta
| Package | 26.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to...
1 affected package
liburi-perl
| Package | 26.04 LTS |
|---|---|
| liburi-perl | Needs evaluation |
Not in release
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed...
1 affected package
rust-zbus-polkit
| Package | 26.04 LTS |
|---|---|
| rust-zbus-polkit | Not in release |
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak...
1 affected package
wordpress
| Package | 26.04 LTS |
|---|---|
| wordpress | Needs evaluation |
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
1 affected package
rlottie
| Package | 26.04 LTS |
|---|---|
| rlottie | Needs evaluation |
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(),...
1 affected package
node-nodemailer
| Package | 26.04 LTS |
|---|---|
| node-nodemailer | Not affected |