Search CVE reports
2561 – 2570 of 59015 results
The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Vulnerable |
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...
1 affected package
dogtag-pki
| Package | 16.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on...
1 affected package
opennebula
| Package | 16.04 LTS |
|---|---|
| opennebula | Needs evaluation |
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend...
1 affected package
nodejs
| Package | 16.04 LTS |
|---|---|
| nodejs | Needs evaluation |
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to...
1 affected package
libjackson-json-java
| Package | 16.04 LTS |
|---|---|
| libjackson-json-java | Needs evaluation |
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how...
1 affected package
popt
| Package | 16.04 LTS |
|---|---|
| popt | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes...
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields....
1 affected package
python-tornado
| Package | 16.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
1 affected package
webkitgtk
| Package | 16.04 LTS |
|---|---|
| webkitgtk | Needs evaluation |
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...
1 affected package
gdb
| Package | 16.04 LTS |
|---|---|
| gdb | Needs evaluation |