Search CVE reports
131 – 140 of 37368 results
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache...
1 affected package
undertow
| Package | 22.04 LTS |
|---|---|
| undertow | Needs evaluation |
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
1 affected package
inkscape
| Package | 22.04 LTS |
|---|---|
| inkscape | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence...
1 affected package
node-brace-expansion
| Package | 22.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar...
1 affected package
calibre
| Package | 22.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's...
1 affected package
calibre
| Package | 22.04 LTS |
|---|---|
| calibre | Needs evaluation |
Not in release
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
1 affected package
grafana
| Package | 22.04 LTS |
|---|---|
| grafana | Not in release |