Search CVE reports
841 – 850 of 42041 results
Not in release
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted...
1 affected package
ruby-pagy
| Package | 24.04 LTS |
|---|---|
| ruby-pagy | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a data: URI,...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
Not in release
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with realpath() . Because normalization strips...
1 affected package
php-dompdf
| Package | 24.04 LTS |
|---|---|
| php-dompdf | Not in release |
A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is...
1 affected package
pglogical
| Package | 24.04 LTS |
|---|---|
| pglogical | Needs evaluation |
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a...
1 affected package
pglogical
| Package | 24.04 LTS |
|---|---|
| pglogical | Needs evaluation |
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which...
1 affected package
pglogical
| Package | 24.04 LTS |
|---|---|
| pglogical | Needs evaluation |