Search CVE reports
141 – 150 of 42133 results
Not in release
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address...
1 affected package
horizon
| Package | 22.04 LTS |
|---|---|
| horizon | Needs evaluation |
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing....
1 affected package
389-ds-base
| Package | 22.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of...
1 affected package
shiro
| Package | 22.04 LTS |
|---|---|
| shiro | Needs evaluation |
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a...
1 affected package
node-ws
| Package | 22.04 LTS |
|---|---|
| node-ws | Needs evaluation |
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not...
1 affected package
ruby-carrierwave
| Package | 22.04 LTS |
|---|---|
| ruby-carrierwave | Needs evaluation |
A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a...
1 affected package
nltk
| Package | 22.04 LTS |
|---|---|
| nltk | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon...
1 affected package
virtualbox
| Package | 22.04 LTS |
|---|---|
| virtualbox | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the...
1 affected package
virtualbox
| Package | 22.04 LTS |
|---|---|
| virtualbox | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon...
1 affected package
virtualbox
| Package | 22.04 LTS |
|---|---|
| virtualbox | Needs evaluation |