Search CVE reports
1441 – 1450 of 28288 results
Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater...
1 affected package
starlette
Package | 24.04 LTS |
---|---|
starlette | Needs evaluation |
In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing theĀ \r and \n UTF-8 characters to separate different messages.
1 affected package
jakarta-mail
Package | 24.04 LTS |
---|---|
jakarta-mail | Needs evaluation |
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled...
1 affected package
pdns-recursor
Package | 24.04 LTS |
---|---|
pdns-recursor | Needs evaluation |
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not...
1 affected package
apache-jena
Package | 24.04 LTS |
---|---|
apache-jena | Needs evaluation |
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
1 affected package
apache-jena
Package | 24.04 LTS |
---|---|
apache-jena | Needs evaluation |
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
1 affected package
wordpress
Package | 24.04 LTS |
---|---|
wordpress | Needs evaluation |
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
1 affected package
mbedtls
Package | 24.04 LTS |
---|---|
mbedtls | Needs evaluation |
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as...
1 affected package
mbedtls
Package | 24.04 LTS |
---|---|
mbedtls | Needs evaluation |
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.
1 affected package
mbedtls
Package | 24.04 LTS |
---|---|
mbedtls | Needs evaluation |
Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way...
1 affected package
ruby-thor
Package | 24.04 LTS |
---|---|
ruby-thor | Needs evaluation |