Search CVE reports
2041 – 2050 of 45973 results
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies...
1 affected package
libcatalyst-plugin-static-simple-perl
| Package | 24.04 LTS |
|---|---|
| libcatalyst-plugin-static-simple-perl | Needs evaluation |
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch...
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS |
|---|---|
| expat | Vulnerable |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Not in release |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Not in release |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | Not in release |
| cableswig | Not in release |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | Not in release |
| smart | Not in release |
| firefox | Not affected |
| thunderbird | Not affected |
| libxmltok | Needs evaluation |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it....
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack....
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init()...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |