Search CVE reports
41 – 50 of 49226 results
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 20.04 LTS |
|---|---|
| kamailio | Needs evaluation |
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...
2 affected packages
varnish, vinyl-cache
| Package | 20.04 LTS |
|---|---|
| varnish | Needs evaluation |
| vinyl-cache | — |
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...
1 affected package
node-uri-js
| Package | 20.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...
1 affected package
node-got
| Package | 20.04 LTS |
|---|---|
| node-got | Needs evaluation |
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...
1 affected package
node-postcss
| Package | 20.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....
1 affected package
node-got
| Package | 20.04 LTS |
|---|---|
| node-got | Needs evaluation |
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...
1 affected package
node-uri-js
| Package | 20.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...
1 affected package
node-braces
| Package | 20.04 LTS |
|---|---|
| node-braces | Needs evaluation |
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and...
1 affected package
xdg-dbus-proxy
| Package | 20.04 LTS |
|---|---|
| xdg-dbus-proxy | Needs evaluation |