Search CVE reports
161 – 170 of 48104 results
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no...
1 affected package
webpy
| Package | 24.04 LTS |
|---|---|
| webpy | Needs evaluation |
webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().
1 affected package
webpy
| Package | 24.04 LTS |
|---|---|
| webpy | Needs evaluation |
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard...
1 affected package
python-anyio
| Package | 24.04 LTS |
|---|---|
| python-anyio | Needs evaluation |
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0,...
1 affected package
jackson-core
| Package | 24.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result,...
1 affected package
webpy
| Package | 24.04 LTS |
|---|---|
| webpy | Needs evaluation |
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory...
58 affected packages
gcc-3.3, gcc-4.6, gcc-4.7, gcc-4.8, gcc-4.9...
| Package | 24.04 LTS |
|---|---|
| gcc-3.3 | Needs evaluation |
| gcc-4.6 | Not in release |
| gcc-4.7 | Not in release |
| gcc-4.8 | Not in release |
| gcc-4.9 | Not in release |
| gcc-5 | Not in release |
| gcc-6 | Not in release |
| gcc-7 | Not in release |
| gcc-8 | Not in release |
| gcc-9 | Needs evaluation |
| gcc-10 | Needs evaluation |
| gcc-11 | Needs evaluation |
| gcc-12 | Needs evaluation |
| gcc-13 | Needs evaluation |
| gcc-4.9-cross | Not in release |
| gcc-5-cross | Not in release |
| gcc-5-cross-ports | Not in release |
| gcc-6-cross | Not in release |
| gcc-6-cross-ports | Not in release |
| gcc-7-cross | Not in release |
| gcc-7-cross-ports | Not in release |
| gcc-8-cross | Not in release |
| gcc-8-cross-ports | Not in release |
| gcc-9-cross | Needs evaluation |
| gcc-9-cross-mipsen | Needs evaluation |
| gcc-9-cross-ports | Needs evaluation |
| gcc-10-cross | Needs evaluation |
| gcc-10-cross-mipsen | Needs evaluation |
| gcc-10-cross-ports | Needs evaluation |
| gcc-11-cross | Needs evaluation |
| gcc-11-cross-mipsen | Needs evaluation |
| gcc-11-cross-ports | Needs evaluation |
| gcc-12-cross | Needs evaluation |
| gcc-12-cross-mipsen | Needs evaluation |
| gcc-12-cross-ports | Needs evaluation |
| gcc-13-cross | Needs evaluation |
| gcc-13-cross-ports | Needs evaluation |
| gcc-or1k-elf | Needs evaluation |
| gcc-riscv64-unknown-elf | Needs evaluation |
| gcc-xtensa-lx106 | Not in release |
| gcc-snapshot | Needs evaluation |
| gcc-i686-linux-android | Not in release |
| gcc-4.7-armel-cross | Not in release |
| gcc-4.7-armhf-cross | Not in release |
| gcc-4.8-arm64-cross | Not in release |
| gcc-4.8-armhf-cross | Not in release |
| gcc-4.8-powerpc-cross | Not in release |
| gcc-4.8-ppc64el-cross | Not in release |
| gcc-arm-linux-androideabi | Not in release |
| gcc-arm-none-eabi | Needs evaluation |
| gcc-avr | Needs evaluation |
| gcc-defaults | Needs evaluation |
| gcc-h8300-hms | Needs evaluation |
| gcc-m68hc1x | Not in release |
| gcc-mingw-w64 | Needs evaluation |
| gcc-msp430 | Not in release |
| gccgo-4.9 | Not in release |
| gccgo-6 | Not in release |
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked...
1 affected package
libreoffice
| Package | 24.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...
1 affected package
libreoffice
| Package | 24.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted...
1 affected package
libreoffice
| Package | 24.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than...
1 affected package
libreoffice
| Package | 24.04 LTS |
|---|---|
| libreoffice | Needs evaluation |