Search CVE reports
2581 – 2590 of 46511 results
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it....
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack....
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Not in release
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init()...
1 affected package
mongoose
| Package | 24.04 LTS |
|---|---|
| mongoose | Not in release |
Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into...
1 affected package
libevent
| Package | 24.04 LTS |
|---|---|
| libevent | Needs evaluation |