Search CVE reports
921 – 930 of 56918 results
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and...
1 affected package
cakephp
| Package | 16.04 LTS |
|---|---|
| cakephp | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled...
1 affected package
cakephp
| Package | 16.04 LTS |
|---|---|
| cakephp | Needs evaluation |
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not...
1 affected package
cakephp
| Package | 16.04 LTS |
|---|---|
| cakephp | Needs evaluation |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines,...
1 affected package
jackson-databind
| Package | 16.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk...
1 affected package
mistune
| Package | 16.04 LTS |
|---|---|
| mistune | Needs evaluation |
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service
1 affected package
aria2
| Package | 16.04 LTS |
|---|---|
| aria2 | Needs evaluation |
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack...
1 affected package
gimp
| Package | 16.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a...
1 affected package
gimp
| Package | 16.04 LTS |
|---|---|
| gimp | Needs evaluation |