Search CVE reports
1081 – 1090 of 57980 results
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 16.04 LTS |
|---|---|
| node-cookies | Needs evaluation |
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript...
1 affected package
evolution
| Package | 16.04 LTS |
|---|---|
| evolution | Needs evaluation |
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided...
1 affected package
pcs
| Package | 16.04 LTS |
|---|---|
| pcs | Not affected |
t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with...
1 affected package
t-digest
| Package | 16.04 LTS |
|---|---|
| t-digest | Needs evaluation |
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents...
2 affected packages
libxfont, libxfont2
| Package | 16.04 LTS |
|---|---|
| libxfont | Needs evaluation |
| libxfont2 | Needs evaluation |
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer....
2 affected packages
libxfont, libxfont2
| Package | 16.04 LTS |
|---|---|
| libxfont | Needs evaluation |
| libxfont2 | Needs evaluation |
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...
1 affected package
libfreemarker-java
| Package | 16.04 LTS |
|---|---|
| libfreemarker-java | Needs evaluation |
An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
1 affected package
gpac
| Package | 16.04 LTS |
|---|---|
| gpac | Needs evaluation |
An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
1 affected package
gpac
| Package | 16.04 LTS |
|---|---|
| gpac | Needs evaluation |
A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in...
1 affected package
gpac
| Package | 16.04 LTS |
|---|---|
| gpac | Needs evaluation |