Search CVE reports
421 – 430 of 56918 results
The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...
1 affected package
freeipa
| Package | 16.04 LTS |
|---|---|
| freeipa | Needs evaluation |
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...
1 affected package
dogtag-pki
| Package | 16.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration...
2 affected packages
resteasy, resteasy3.0
| Package | 16.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | — |
(Predis is a flexible and feature-complete Redis and Valkey client for ...)
1 affected package
php-nrk-predis
| Package | 16.04 LTS |
|---|---|
| php-nrk-predis | Needs evaluation |
(Scrapy is a high-level web crawling and scraping framework for Python. ...)
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 16.04 LTS |
|---|---|
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | Needs evaluation |
| python3.6 | — |
| python3.7 | — |
| python3.8 | — |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and...
1 affected package
composer
| Package | 16.04 LTS |
|---|---|
| composer | Needs evaluation |
(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and...
3 affected packages
phpseclib, php-phpseclib, php-phpseclib3
| Package | 16.04 LTS |
|---|---|
| phpseclib | Needs evaluation |
| php-phpseclib | Needs evaluation |
| php-phpseclib3 | — |