Search CVE reports
1761 – 1770 of 45973 results
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value...
1 affected package
hugo
| Package | 24.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern...
1 affected package
hugo
| Package | 24.04 LTS |
|---|---|
| hugo | Needs evaluation |
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a...
1 affected package
node-ajv
| Package | 24.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its...
1 affected package
node-ajv
| Package | 24.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn...
1 affected package
node-ajv
| Package | 24.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
Not in release
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When...
1 affected package
lxd
| Package | 24.04 LTS |
|---|---|
| lxd | Not in release |
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can...
1 affected package
libwebsockets
| Package | 24.04 LTS |
|---|---|
| libwebsockets | Needs evaluation |
Not in release
A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
Not in release
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the...
1 affected package
llama.cpp
| Package | 24.04 LTS |
|---|---|
| llama.cpp | Not in release |
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf,...
1 affected package
libdbd-pg-perl
| Package | 24.04 LTS |
|---|---|
| libdbd-pg-perl | Needs evaluation |