Search CVE reports
2471 – 2480 of 46511 results
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex...
1 affected package
libtie-hash-regex-perl
| Package | 24.04 LTS |
|---|---|
| libtie-hash-regex-perl | Needs evaluation |
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify...
1 affected package
weechat
| Package | 24.04 LTS |
|---|---|
| weechat | Needs evaluation |
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on...
1 affected package
weechat
| Package | 24.04 LTS |
|---|---|
| weechat | Needs evaluation |
FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a...
1 affected package
fort-validator
| Package | 24.04 LTS |
|---|---|
| fort-validator | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter...
1 affected package
golang-github-getkin-kin-openapi
| Package | 24.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |