Search CVE reports
431 – 440 of 57488 results
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...
2 affected packages
glibc, eglibc
| Package | 16.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds...
1 affected package
gst-plugins-good1.0
| Package | 16.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 16.04 LTS |
|---|---|
| node-cookies | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
mongo-java-driver
| Package | 16.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...
1 affected package
mongo-java-driver
| Package | 16.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
ruby-mongo
| Package | 16.04 LTS |
|---|---|
| ruby-mongo | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
pymongo
| Package | 16.04 LTS |
|---|---|
| pymongo | Needs evaluation |
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...
12 affected packages
pypy3, python2.7, python3.4, python3.5, python3.6...
| Package | 16.04 LTS |
|---|---|
| pypy3 | — |
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | Needs evaluation |
| python3.6 | — |
| python3.7 | — |
| python3.8 | — |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...
1 affected package
node-multiparty
| Package | 16.04 LTS |
|---|---|
| node-multiparty | Needs evaluation |
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...
1 affected package
node-compression
| Package | 16.04 LTS |
|---|---|
| node-compression | Needs evaluation |