Search CVE reports
2531 – 2540 of 59015 results
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of...
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document...
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy...
7 affected packages
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...
| Package | 16.04 LTS |
|---|---|
| ruby2.3 | Needs evaluation |
| ruby2.5 | — |
| ruby2.7 | — |
| ruby3.0 | — |
| ruby3.2 | — |
| ruby3.3 | — |
| jruby | Needs evaluation |
phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and...
3 affected packages
phpseclib, php-phpseclib, php-phpseclib3
| Package | 16.04 LTS |
|---|---|
| phpseclib | Needs evaluation |
| php-phpseclib | Needs evaluation |
| php-phpseclib3 | — |
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in...
1 affected package
sqlparse
| Package | 16.04 LTS |
|---|---|
| sqlparse | Needs evaluation |
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume...
3 affected packages
golang-google-grpc, google-guest-agent, grpc
| Package | 16.04 LTS |
|---|---|
| golang-google-grpc | Needs evaluation |
| google-guest-agent | Needs evaluation |
| grpc | Needs evaluation |
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata...
3 affected packages
golang-google-grpc, google-guest-agent, grpc
| Package | 16.04 LTS |
|---|---|
| golang-google-grpc | Needs evaluation |
| google-guest-agent | Needs evaluation |
| grpc | Needs evaluation |
FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.
2 affected packages
ffmpeg, libav
| Package | 16.04 LTS |
|---|---|
| ffmpeg | Needs evaluation |
| libav | — |
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing...
1 affected package
kamailio
| Package | 16.04 LTS |
|---|---|
| kamailio | Needs evaluation |
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
1 affected package
kamailio
| Package | 16.04 LTS |
|---|---|
| kamailio | Needs evaluation |