Search CVE reports
131 – 140 of 52029 results
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...
1 affected package
cockpit
| Package | 22.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...
1 affected package
cockpit
| Package | 22.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 22.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 22.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing...
1 affected package
jupyter-server
| Package | 22.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character...
1 affected package
soupsieve
| Package | 22.04 LTS |
|---|---|
| soupsieve | Needs evaluation |
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC...
1 affected package
soupsieve
| Package | 22.04 LTS |
|---|---|
| soupsieve | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |