Search CVE reports
1 – 10 of 52620 results
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on...
1 affected package
apr-util
| Package | 16.04 LTS |
|---|---|
| apr-util | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...
1 affected package
python-django
| Package | 16.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...
1 affected package
python-django
| Package | 16.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...
1 affected package
python-django
| Package | 16.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor....
1 affected package
python-django
| Package | 16.04 LTS |
|---|---|
| python-django | Needs evaluation |
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal...
1 affected package
popt
| Package | 16.04 LTS |
|---|---|
| popt | Needs evaluation |
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
1 affected package
openvpn
| Package | 16.04 LTS |
|---|---|
| openvpn | Needs evaluation |
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 16.04 LTS |
|---|---|
| php5 | — |
| php7.0 | Needs evaluation |
| php7.2 | — |
| php7.4 | — |
| php8.1 | — |
| php8.3 | — |
| php8.5 | — |
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 16.04 LTS |
|---|---|
| php5 | — |
| php7.0 | Needs evaluation |
| php7.2 | — |
| php7.4 | — |
| php8.1 | — |
| php8.3 | — |
| php8.5 | — |
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a...
1 affected package
sg3-utils
| Package | 16.04 LTS |
|---|---|
| sg3-utils | Needs evaluation |