Search CVE reports
141 – 150 of 53512 results
Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send...
1 affected package
python-tornado
| Package | 22.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the...
1 affected package
rpm
| Package | 22.04 LTS |
|---|---|
| rpm | Needs evaluation |
A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The...
1 affected package
gpac
| Package | 22.04 LTS |
|---|---|
| gpac | Needs evaluation |
A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow....
1 affected package
ghostscript
| Package | 22.04 LTS |
|---|---|
| ghostscript | Needs evaluation |
Not in release
A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow....
1 affected package
c-blosc2
| Package | 22.04 LTS |
|---|---|
| c-blosc2 | Not in release |
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in...
1 affected package
graphicsmagick
| Package | 22.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application...
1 affected package
pyjwt
| Package | 22.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label...
2 affected packages
pypdf, pypdf2
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |
| pypdf2 | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for...
2 affected packages
pypdf, pypdf2
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |
| pypdf2 | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work...
2 affected packages
pypdf, pypdf2
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |
| pypdf2 | Needs evaluation |