Search CVE reports
41 – 50 of 46920 results
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts...
1 affected package
undertow
| Package | 20.04 LTS |
|---|---|
| undertow | Needs evaluation |
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak...
1 affected package
wordpress
| Package | 20.04 LTS |
|---|---|
| wordpress | Needs evaluation |
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to...
1 affected package
libjackson-json-java
| Package | 20.04 LTS |
|---|---|
| libjackson-json-java | Needs evaluation |
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how...
1 affected package
popt
| Package | 20.04 LTS |
|---|---|
| popt | Needs evaluation |
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...
1 affected package
gdb
| Package | 20.04 LTS |
|---|---|
| gdb | Needs evaluation |
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with...
1 affected package
node-nodemailer
| Package | 20.04 LTS |
|---|---|
| node-nodemailer | Needs evaluation |
A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to...
1 affected package
kamailio
| Package | 20.04 LTS |
|---|---|
| kamailio | Needs evaluation |
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the...
1 affected package
assimp
| Package | 20.04 LTS |
|---|---|
| assimp | Needs evaluation |
### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while...
1 affected package
node-qs
| Package | 20.04 LTS |
|---|---|
| node-qs | Needs evaluation |
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...
1 affected package
sudo
| Package | 20.04 LTS |
|---|---|
| sudo | Needs evaluation |