Search CVE reports
981 – 990 of 49237 results
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only...
1 affected package
swift
| Package | 24.04 LTS |
|---|---|
| swift | Needs evaluation |
DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious...
1 affected package
dcmtk
| Package | 24.04 LTS |
|---|---|
| dcmtk | Needs evaluation |
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can...
1 affected package
node-sprintf-js
| Package | 24.04 LTS |
|---|---|
| node-sprintf-js | Needs evaluation |
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while...
1 affected package
rpm
| Package | 24.04 LTS |
|---|---|
| rpm | Needs evaluation |
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because...
1 affected package
rpm
| Package | 24.04 LTS |
|---|---|
| rpm | Needs evaluation |