Search CVE reports
51 – 60 of 47927 results
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...
1 affected package
node-uri-js
| Package | 24.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...
1 affected package
node-got
| Package | 24.04 LTS |
|---|---|
| node-got | Needs evaluation |
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...
1 affected package
node-postcss
| Package | 24.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....
1 affected package
node-got
| Package | 24.04 LTS |
|---|---|
| node-got | Needs evaluation |
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...
1 affected package
node-uri-js
| Package | 24.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...
1 affected package
node-braces
| Package | 24.04 LTS |
|---|---|
| node-braces | Needs evaluation |
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and...
1 affected package
xdg-dbus-proxy
| Package | 24.04 LTS |
|---|---|
| xdg-dbus-proxy | Needs evaluation |
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership...
1 affected package
rust-coreutils
| Package | 24.04 LTS |
|---|---|
| rust-coreutils | Needs evaluation |
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results....
1 affected package
rust-hickory-resolver
| Package | 24.04 LTS |
|---|---|
| rust-hickory-resolver | Needs evaluation |
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count...
1 affected package
poppler
| Package | 24.04 LTS |
|---|---|
| poppler | Needs evaluation |