Search CVE reports
11 – 20 of 36556 results
Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being...
1 affected package
dask.distributed
| Package | 20.04 LTS |
|---|---|
| dask.distributed | Needs evaluation |
[Privilege Escalation via Identity Headers in External OAuth2 Tokens]
1 affected package
python-keystonemiddleware
| Package | 20.04 LTS |
|---|---|
| python-keystonemiddleware | Not affected |
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...
1 affected package
libxml2
| Package | 20.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...
1 affected package
libxml2
| Package | 20.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...
1 affected package
libxml2
| Package | 20.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
Integer overflow in g_buffered_input_stream_peek() leads to segmentation fault
1 affected package
glib2.0
| Package | 20.04 LTS |
|---|---|
| glib2.0 | Needs evaluation |
getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
2 affected packages
glibc, eglibc
| Package | 20.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can...
1 affected package
plantuml
| Package | 20.04 LTS |
|---|---|
| plantuml | Needs evaluation |
A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.
1 affected package
gpac
| Package | 20.04 LTS |
|---|---|
| gpac | Needs evaluation |
A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.
1 affected package
gpac
| Package | 20.04 LTS |
|---|---|
| gpac | Needs evaluation |