Search CVE reports
2081 – 2090 of 43788 results
Not in release
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust...
1 affected package
thumbor
| Package | 24.04 LTS |
|---|---|
| thumbor | Not in release |
Not in release
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension...
1 affected package
thumbor
| Package | 24.04 LTS |
|---|---|
| thumbor | Not in release |
Not in release
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through...
1 affected package
thumbor
| Package | 24.04 LTS |
|---|---|
| thumbor | Not in release |
Not in release
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since...
1 affected package
thumbor
| Package | 24.04 LTS |
|---|---|
| thumbor | Not in release |
Not in release
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the...
1 affected package
thumbor
| Package | 24.04 LTS |
|---|---|
| thumbor | Not in release |
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
1 affected package
ntpsec
| Package | 24.04 LTS |
|---|---|
| ntpsec | Needs evaluation |
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive...
1 affected package
onionshare
| Package | 24.04 LTS |
|---|---|
| onionshare | Needs evaluation |
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links...
1 affected package
onionshare
| Package | 24.04 LTS |
|---|---|
| onionshare | Needs evaluation |
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or...
1 affected package
node-ajv
| Package | 24.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing...
1 affected package
gnome-remote-desktop
| Package | 24.04 LTS |
|---|---|
| gnome-remote-desktop | Needs evaluation |