Search CVE reports
111 – 120 of 34709 results
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the...
1 affected package
sqlparse
| Package | 26.04 LTS |
|---|---|
| sqlparse | Needs evaluation |
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment...
1 affected package
sqlparse
| Package | 26.04 LTS |
|---|---|
| sqlparse | Needs evaluation |
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case,...
1 affected package
sqlparse
| Package | 26.04 LTS |
|---|---|
| sqlparse | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache...
1 affected package
glances
| Package | 26.04 LTS |
|---|---|
| glances | Needs evaluation |
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin...
1 affected package
glances
| Package | 26.04 LTS |
|---|---|
| glances | Needs evaluation |
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError,...
1 affected package
ruby-websocket-driver
| Package | 26.04 LTS |
|---|---|
| ruby-websocket-driver | Needs evaluation |
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values...
1 affected package
node-postcss
| Package | 26.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is...
1 affected package
node-extract-zip
| Package | 26.04 LTS |
|---|---|
| node-extract-zip | Needs evaluation |