Search CVE reports
31 – 40 of 58662 results
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0,...
1 affected package
jackson-core
| Package | 16.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result,...
1 affected package
webpy
| Package | 16.04 LTS |
|---|---|
| webpy | Needs evaluation |
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory...
58 affected packages
gcc-3.3, gcc-4.6, gcc-4.7, gcc-4.8, gcc-4.9...
| Package | 16.04 LTS |
|---|---|
| gcc-3.3 | Needs evaluation |
| gcc-4.6 | — |
| gcc-4.7 | Needs evaluation |
| gcc-4.8 | Needs evaluation |
| gcc-4.9 | Needs evaluation |
| gcc-5 | Needs evaluation |
| gcc-6 | — |
| gcc-7 | — |
| gcc-8 | — |
| gcc-9 | — |
| gcc-10 | — |
| gcc-11 | — |
| gcc-12 | — |
| gcc-13 | — |
| gcc-4.9-cross | Needs evaluation |
| gcc-5-cross | Needs evaluation |
| gcc-5-cross-ports | Needs evaluation |
| gcc-6-cross | — |
| gcc-6-cross-ports | — |
| gcc-7-cross | — |
| gcc-7-cross-ports | — |
| gcc-8-cross | — |
| gcc-8-cross-ports | — |
| gcc-9-cross | — |
| gcc-9-cross-mipsen | — |
| gcc-9-cross-ports | — |
| gcc-10-cross | — |
| gcc-10-cross-mipsen | — |
| gcc-10-cross-ports | — |
| gcc-11-cross | — |
| gcc-11-cross-mipsen | — |
| gcc-11-cross-ports | — |
| gcc-12-cross | — |
| gcc-12-cross-mipsen | — |
| gcc-12-cross-ports | — |
| gcc-13-cross | — |
| gcc-13-cross-ports | — |
| gcc-or1k-elf | — |
| gcc-riscv64-unknown-elf | — |
| gcc-xtensa-lx106 | — |
| gcc-snapshot | Needs evaluation |
| gcc-i686-linux-android | Needs evaluation |
| gcc-4.7-armel-cross | Needs evaluation |
| gcc-4.7-armhf-cross | Needs evaluation |
| gcc-4.8-arm64-cross | Needs evaluation |
| gcc-4.8-armhf-cross | Needs evaluation |
| gcc-4.8-powerpc-cross | Needs evaluation |
| gcc-4.8-ppc64el-cross | Needs evaluation |
| gcc-arm-linux-androideabi | Needs evaluation |
| gcc-arm-none-eabi | Needs evaluation |
| gcc-avr | Needs evaluation |
| gcc-defaults | Needs evaluation |
| gcc-h8300-hms | Needs evaluation |
| gcc-m68hc1x | Needs evaluation |
| gcc-mingw-w64 | Needs evaluation |
| gcc-msp430 | Needs evaluation |
| gccgo-4.9 | — |
| gccgo-6 | Needs evaluation |
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote...
1 affected package
rpcbind
| Package | 16.04 LTS |
|---|---|
| rpcbind | Needs evaluation |
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments,...
1 affected package
libdancer2-perl
| Package | 16.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the...
1 affected package
libdancer2-perl
| Package | 16.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup...
1 affected package
libdancer2-perl
| Package | 16.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text,...
1 affected package
libdancer2-perl
| Package | 16.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |