Search CVE reports
671 – 680 of 37626 results
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause...
1 affected package
multipath-tools
| Package | 26.04 LTS |
|---|---|
| multipath-tools | Needs evaluation |
Not in release
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...
12 affected packages
pypy3, python2.7, python3.4, python3.5, python3.6...
| Package | 26.04 LTS |
|---|---|
| pypy3 | Needs evaluation |
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Not in release |
| python3.14 | Needs evaluation |
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URLĀ - contain ambiguous nested quantifiers. An application that obtains...
1 affected package
apache-opennlp
| Package | 26.04 LTS |
|---|---|
| apache-opennlp | Needs evaluation |
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
1 affected package
wpa
| Package | 26.04 LTS |
|---|---|
| wpa | Needs evaluation |
OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not...
1 affected package
apache-opennlp
| Package | 26.04 LTS |
|---|---|
| apache-opennlp | Needs evaluation |
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file,...
5 affected packages
tiff, qtwebengine-opensource-src, texmaker, gdal, neuron
| Package | 26.04 LTS |
|---|---|
| tiff | Needs evaluation |
| qtwebengine-opensource-src | Needs evaluation |
| texmaker | Not affected |
| gdal | Not affected |
| neuron | Not affected |
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an...
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without...
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word...
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |