Search CVE reports


Toggle filters

881 – 890 of 56918 results

Status is adjusted based on your filters.


CVE-2025-71346

Medium priority
Needs evaluation

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2024-58378

Medium priority
Needs evaluation

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader....

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2024-58377

Medium priority
Needs evaluation

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2023-54354

Medium priority
Needs evaluation

Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2022-51000

Medium priority
Needs evaluation

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2022-50999

Medium priority
Needs evaluation

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2022-50998

Medium priority
Needs evaluation

Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2021-47996

Medium priority
Needs evaluation

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in...

1 affected package

ruby-nokogiri

Package 16.04 LTS
ruby-nokogiri Needs evaluation
Show less packages

CVE-2026-16599

Medium priority
Needs evaluation

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without...

1 affected package

wget

Package 16.04 LTS
wget Needs evaluation
Show less packages

CVE-2026-15310

Medium priority
Needs evaluation

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4
python3.5 Needs evaluation
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.14
Show all 11 packages Show less packages