Search CVE reports
121 – 130 of 49410 results
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and...
1 affected package
apache2
| Package | 24.04 LTS |
|---|---|
| apache2 | Needs evaluation |
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then...
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 24.04 LTS |
|---|---|
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Needs evaluation |
| python3.14 | Not in release |
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and...
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 24.04 LTS |
|---|---|
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Needs evaluation |
| python3.14 | Not in release |
[GHSA-wj29-mxmc-q98c: Heap OOB read/write in MS-MPPE key re-encryption]
1 affected package
radsecproxy
| Package | 24.04 LTS |
|---|---|
| radsecproxy | Needs evaluation |
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor...
1 affected package
node-katex
| Package | 24.04 LTS |
|---|---|
| node-katex | Needs evaluation |
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content...
1 affected package
ansible-runner
| Package | 24.04 LTS |
|---|---|
| ansible-runner | Needs evaluation |
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is...
1 affected package
tnef
| Package | 24.04 LTS |
|---|---|
| tnef | Needs evaluation |
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper...
1 affected package
tnef
| Package | 24.04 LTS |
|---|---|
| tnef | Needs evaluation |
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input...
1 affected package
tnef
| Package | 24.04 LTS |
|---|---|
| tnef | Needs evaluation |
A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application...
1 affected package
gegl
| Package | 24.04 LTS |
|---|---|
| gegl | Needs evaluation |