Search CVE reports
371 – 380 of 42523 results
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the...
2 affected packages
glibc, eglibc
| Package | 18.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server,...
2 affected packages
glibc, eglibc
| Package | 18.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing...
14 affected packages
jython, pypy3, python2.7, python3.4, python3.5...
| Package | 18.04 LTS |
|---|---|
| jython | Needs evaluation |
| pypy3 | — |
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | — |
| python3.6 | Needs evaluation |
| python3.7 | Needs evaluation |
| python3.8 | Needs evaluation |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.13 | — |
| python3.14 | — |
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past...
1 affected package
pjproject
| Package | 18.04 LTS |
|---|---|
| pjproject | Needs evaluation |
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's...
1 affected package
pjproject
| Package | 18.04 LTS |
|---|---|
| pjproject | Needs evaluation |
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between...
1 affected package
pjproject
| Package | 18.04 LTS |
|---|---|
| pjproject | Needs evaluation |
pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the...
1 affected package
pydicom
| Package | 18.04 LTS |
|---|---|
| pydicom | Needs evaluation |
[Unknown description]
1 affected package
qemu
| Package | 18.04 LTS |
|---|---|
| qemu | Needs evaluation |
tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a...
23 affected packages
rust-tar, rustc, rustc-1.62, rustc-1.74, rustc-1.76...
| Package | 18.04 LTS |
|---|---|
| rust-tar | — |
| rustc | Needs evaluation |
| rustc-1.62 | — |
| rustc-1.74 | — |
| rustc-1.76 | — |
| rustc-1.77 | — |
| rustc-1.78 | — |
| rustc-1.79 | — |
| rustc-1.80 | — |
| rustc-1.81 | — |
| rustc-1.82 | — |
| rustc-1.83 | — |
| rustc-1.84 | — |
| rustc-1.85 | — |
| rustc-1.88 | — |
| rustc-1.89 | — |
| rustc-1.91 | — |
| rustc-1.92 | — |
| rustc-1.93 | — |
| cargo | Needs evaluation |
| rust-cargo-c | — |
| rust-async-tar | — |
| rust-astral-tokio-tar | — |
phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue...
3 affected packages
php-phpseclib, php-phpseclib3, phpseclib
| Package | 18.04 LTS |
|---|---|
| php-phpseclib | Needs evaluation |
| php-phpseclib3 | — |
| phpseclib | Needs evaluation |