Search CVE reports
951 – 960 of 43643 results
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 24.04 LTS |
|---|---|
| postgresql-18 | Not in release |
| postgresql-16 | Needs evaluation |
| postgresql-14 | Not in release |
| postgresql-12 | Not in release |
| postgresql-10 | Not in release |
| postgresql-9.5 | Not in release |
| postgresql-9.3 | Not in release |
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 24.04 LTS |
|---|---|
| openssl | Needs evaluation |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
(HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)
1 affected package
libhtml-formhandler-perl
| Package | 24.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which...
1 affected package
python-tablib
| Package | 24.04 LTS |
|---|---|
| python-tablib | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil...
1 affected package
golang-github-getkin-kin-openapi
| Package | 24.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...
1 affected package
etcd
| Package | 24.04 LTS |
|---|---|
| etcd | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey()...
1 affected package
etcd
| Package | 24.04 LTS |
|---|---|
| etcd | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs...
1 affected package
ruby-loofah
| Package | 24.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |