Search CVE reports
1741 – 1750 of 45973 results
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
Not in release
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and...
1 affected package
cakephp
| Package | 24.04 LTS |
|---|---|
| cakephp | Not in release |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not...
1 affected package
golang-opentelemetry-otel
| Package | 24.04 LTS |
|---|---|
| golang-opentelemetry-otel | Needs evaluation |
Not in release
A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request...
1 affected package
cri-o
| Package | 24.04 LTS |
|---|---|
| cri-o | Not in release |
Not in release
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled...
1 affected package
cakephp
| Package | 24.04 LTS |
|---|---|
| cakephp | Not in release |
Not in release
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not...
1 affected package
cakephp
| Package | 24.04 LTS |
|---|---|
| cakephp | Not in release |
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines,...
1 affected package
jackson-databind
| Package | 24.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk...
1 affected package
mistune
| Package | 24.04 LTS |
|---|---|
| mistune | Needs evaluation |