Search CVE reports
1071 – 1080 of 57980 results
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
ruby-mongo
| Package | 16.04 LTS |
|---|---|
| ruby-mongo | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component....
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions....
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract...
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled...
1 affected package
gvfs
| Package | 16.04 LTS |
|---|---|
| gvfs | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |