Search CVE reports
161 – 170 of 42176 results
(Use after free in WebShare in Google Chrome on Windows prior to 149.0. ...)
1 affected package
chromium-browser
| Package | 22.04 LTS |
|---|---|
| chromium-browser | Not affected |
(When NGINX Plus is configured as the data plane for NGINX Gateway Fabr ...)
1 affected package
nginx
| Package | 22.04 LTS |
|---|---|
| nginx | Not affected |
Not in release
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying...
1 affected package
joserfc
| Package | 22.04 LTS |
|---|---|
| joserfc | Not in release |
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly...
1 affected package
node-markdown-it
| Package | 22.04 LTS |
|---|---|
| node-markdown-it | Needs evaluation |
PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes...
8 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 22.04 LTS |
|---|---|
| php5 | Not in release |
| php7.0 | Not in release |
| php7.2 | Not in release |
| php7.4 | Not in release |
| php8.1 | Needs evaluation |
| php8.3 | Not in release |
| php8.4 | Not in release |
| php8.5 | Not in release |
Not in release
Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process,...
1 affected package
shaarli
| Package | 22.04 LTS |
|---|---|
| shaarli | Not in release |
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass...
1 affected package
tinyproxy
| Package | 22.04 LTS |
|---|---|
| tinyproxy | Needs evaluation |
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with...
1 affected package
libssh2
| Package | 22.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion...
1 affected package
libssh2
| Package | 22.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine...
1 affected package
tinyproxy
| Package | 22.04 LTS |
|---|---|
| tinyproxy | Needs evaluation |