Search CVE reports
1 – 10 of 56459 results
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
1 affected package
webkitgtk
| Package | 16.04 LTS |
|---|---|
| webkitgtk | Needs evaluation |
A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The...
1 affected package
flvmeta
| Package | 16.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow....
1 affected package
flvmeta
| Package | 16.04 LTS |
|---|---|
| flvmeta | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes...
2 affected packages
pypdf, pypdf2
| Package | 16.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields....
1 affected package
python-tornado
| Package | 16.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts...
1 affected package
undertow
| Package | 16.04 LTS |
|---|---|
| undertow | Needs evaluation |
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak...
1 affected package
wordpress
| Package | 16.04 LTS |
|---|---|
| wordpress | Needs evaluation |
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to...
1 affected package
libjackson-json-java
| Package | 16.04 LTS |
|---|---|
| libjackson-json-java | Needs evaluation |
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how...
1 affected package
popt
| Package | 16.04 LTS |
|---|---|
| popt | Needs evaluation |
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...
1 affected package
gdb
| Package | 16.04 LTS |
|---|---|
| gdb | Needs evaluation |