Search CVE reports
281 – 290 of 40129 results
A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use...
1 affected package
opendkim
| Package | 26.04 LTS |
|---|---|
| opendkim | Needs evaluation |
[lxc-copy host-context hostname update follows symlink]
1 affected package
lxc
| Package | 26.04 LTS |
|---|---|
| lxc | Needs evaluation |
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are...
1 affected package
zoneminder
| Package | 26.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response...
1 affected package
zoneminder
| Package | 26.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to...
1 affected package
zoneminder
| Package | 26.04 LTS |
|---|---|
| zoneminder | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member...
1 affected package
node-brace-expansion
| Package | 26.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing...
1 affected package
node-brace-expansion
| Package | 26.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts...
1 affected package
node-brace-expansion
| Package | 26.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d...
1 affected package
pyjwt
| Package | 26.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs...
1 affected package
pyjwt
| Package | 26.04 LTS |
|---|---|
| pyjwt | Needs evaluation |