Search CVE reports
1 – 10 of 46748 results
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...
1 affected package
node-tar
| Package | 16.04 LTS |
|---|---|
| node-tar | Needs evaluation |
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
1 affected package
cakephp
| Package | 16.04 LTS |
|---|---|
| cakephp | Needs evaluation |
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
1 affected package
pyasn1
| Package | 16.04 LTS |
|---|---|
| pyasn1 | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 16.04 LTS |
|---|---|
| gradle | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 16.04 LTS |
|---|---|
| gradle | Needs evaluation |
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot...
3 affected packages
secureboot-db, shim-signed, shim
| Package | 16.04 LTS |
|---|---|
| secureboot-db | Ignored |
| shim-signed | Ignored |
| shim | Ignored |
(GitLab has remediated a security issue in GitLab CE/EE affecting all v ...)
1 affected package
gitlab
| Package | 16.04 LTS |
|---|---|
| gitlab | Ignored |
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow....
1 affected package
mapnik
| Package | 16.04 LTS |
|---|---|
| mapnik | Needs evaluation |
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The...
1 affected package
opencc
| Package | 16.04 LTS |
|---|---|
| opencc | Needs evaluation |
(GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
1 affected package
gitlab
| Package | 16.04 LTS |
|---|---|
| gitlab | Ignored |