Search CVE reports
181 – 190 of 33329 results
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH...
1 affected package
python-ecdsa
| Package | 24.04 LTS |
|---|---|
| python-ecdsa | Needs evaluation |
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to...
1 affected package
cgif
| Package | 24.04 LTS |
|---|---|
| cgif | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings —...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials`...
1 affected package
node-handlebars
| Package | 24.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Not in release
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an...
1 affected package
node-node-forge
| Package | 24.04 LTS |
|---|---|
| node-node-forge | Not in release |
Not in release
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not...
1 affected package
node-node-forge
| Package | 24.04 LTS |
|---|---|
| node-node-forge | Not in release |