Search CVE reports
1 – 10 of 31440 results
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...
1 affected package
node-tar
| Package | 24.04 LTS |
|---|---|
| node-tar | Needs evaluation |
Not in release
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
1 affected package
cakephp
| Package | 24.04 LTS |
|---|---|
| cakephp | Not in release |
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
1 affected package
wlc
| Package | 24.04 LTS |
|---|---|
| wlc | Needs evaluation |
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
1 affected package
pyasn1
| Package | 24.04 LTS |
|---|---|
| pyasn1 | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 24.04 LTS |
|---|---|
| gradle | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 24.04 LTS |
|---|---|
| gradle | Needs evaluation |
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot...
3 affected packages
secureboot-db, shim-signed, shim
| Package | 24.04 LTS |
|---|---|
| secureboot-db | Not affected |
| shim-signed | Not affected |
| shim | Not affected |
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed...
1 affected package
quickjs
| Package | 24.04 LTS |
|---|---|
| quickjs | Needs evaluation |
Not in release
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball,...
1 affected package
libharfbuzz-shaper-perl
| Package | 24.04 LTS |
|---|---|
| libharfbuzz-shaper-perl | Not in release |
Not in release
(Allocation of Resources Without Limits or Throttling in the HDF5 weigh ...)
1 affected package
keras
| Package | 24.04 LTS |
|---|---|
| keras | Not in release |