Search CVE reports
1981 – 1990 of 43788 results
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the...
1 affected package
node-ip-address
| Package | 24.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser,...
1 affected package
node-ip-address
| Package | 24.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer...
1 affected package
node-socket.io-parser
| Package | 24.04 LTS |
|---|---|
| node-socket.io-parser | Needs evaluation |
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an...
1 affected package
node-postcss
| Package | 24.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or...
1 affected package
node-brace-expansion
| Package | 24.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and...
1 affected package
angular.js
| Package | 24.04 LTS |
|---|---|
| angular.js | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in...
1 affected package
angular.js
| Package | 24.04 LTS |
|---|---|
| angular.js | Needs evaluation |
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters,...
1 affected package
angular.js
| Package | 24.04 LTS |
|---|---|
| angular.js | Needs evaluation |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which...
1 affected package
apache-jena
| Package | 24.04 LTS |
|---|---|
| apache-jena | Needs evaluation |
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has...
1 affected package
tar
| Package | 24.04 LTS |
|---|---|
| tar | Needs evaluation |