Search CVE reports
181 – 190 of 53339 results
urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after...
2 affected packages
python-urllib3, python-pip
| Package | 22.04 LTS |
|---|---|
| python-urllib3 | Needs evaluation |
| python-pip | Needs evaluation |
urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE...
2 affected packages
python-urllib3, python-pip
| Package | 22.04 LTS |
|---|---|
| python-urllib3 | Needs evaluation |
| python-pip | Needs evaluation |
Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats...
1 affected package
php-league-flysystem
| Package | 22.04 LTS |
|---|---|
| php-league-flysystem | Needs evaluation |
Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first...
1 affected package
python-werkzeug
| Package | 22.04 LTS |
|---|---|
| python-werkzeug | Needs evaluation |
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with...
1 affected package
golang-github-klauspost-compress
| Package | 22.04 LTS |
|---|---|
| golang-github-klauspost-compress | Needs evaluation |
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 22.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Vulnerable |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Ignored |
| mozjs91 | Ignored |
| mozjs102 | Ignored |
| mozjs115 | Not in release |
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to...
1 affected package
pypy3
| Package | 22.04 LTS |
|---|---|
| pypy3 | Needs evaluation |
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 22.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Vulnerable |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Ignored |
| mozjs91 | Ignored |
| mozjs102 | Ignored |
| mozjs115 | Not in release |