Search CVE reports
1161 – 1170 of 56918 results
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain...
1 affected package
spip
| Package | 16.04 LTS |
|---|---|
| spip | Needs evaluation |
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because...
1 affected package
xapian-core
| Package | 16.04 LTS |
|---|---|
| xapian-core | Needs evaluation |
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities....
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active...
1 affected package
capstone
| Package | 16.04 LTS |
|---|---|
| capstone | Needs evaluation |
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without...
1 affected package
capstone
| Package | 16.04 LTS |
|---|---|
| capstone | Needs evaluation |
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and...
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which ...
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is...
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
1 affected package
tor
| Package | 16.04 LTS |
|---|---|
| tor | Needs evaluation |