Search CVE reports
761 – 770 of 32959 results
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when...
1 affected package
imagemagick
| Package | 26.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to...
1 affected package
node-undici
| Package | 26.04 LTS |
|---|---|
| node-undici | Needs evaluation |
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the...
1 affected package
node-undici
| Package | 26.04 LTS |
|---|---|
| node-undici | Needs evaluation |
undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to...
1 affected package
node-undici
| Package | 26.04 LTS |
|---|---|
| node-undici | Needs evaluation |
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
1 affected package
pgvector
| Package | 26.04 LTS |
|---|---|
| pgvector | Needs evaluation |
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts JWTs with trailing padding (==) which are not conforming to...
1 affected package
joserfc
| Package | 26.04 LTS |
|---|---|
| joserfc | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version:...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package...
2 affected packages
pipenv, python-pip
| Package | 26.04 LTS |
|---|---|
| pipenv | Needs evaluation |
| python-pip | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in CONNECT and...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |