Search CVE reports
91 – 100 of 47927 results
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9...
1 affected package
wordpress
| Package | 24.04 LTS |
|---|---|
| wordpress | Needs evaluation |
Not in release
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit...
1 affected package
sogo
| Package | 24.04 LTS |
|---|---|
| sogo | Not in release |
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the...
1 affected package
snappy-java
| Package | 24.04 LTS |
|---|---|
| snappy-java | Needs evaluation |
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native...
1 affected package
snappy-java
| Package | 24.04 LTS |
|---|---|
| snappy-java | Needs evaluation |
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer...
1 affected package
mongo-c-driver
| Package | 24.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message....
1 affected package
mongo-c-driver
| Package | 24.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data...
1 affected package
mongo-c-driver
| Package | 24.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
| Package | 24.04 LTS |
|---|---|
| chromium-browser | Not affected |