Search CVE reports
2741 – 2750 of 46511 results
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive...
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the...
1 affected package
kraken
| Package | 24.04 LTS |
|---|---|
| kraken | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose...
1 affected package
golang-github-getkin-kin-openapi
| Package | 24.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |
Not in release
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line...
1 affected package
aiosmtplib
| Package | 24.04 LTS |
|---|---|
| aiosmtplib | Not in release |
WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background...
1 affected package
weasyprint
| Package | 24.04 LTS |
|---|---|
| weasyprint | Needs evaluation |
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and...
1 affected package
rabbitmq-java-client
| Package | 24.04 LTS |
|---|---|
| rabbitmq-java-client | Needs evaluation |
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept...
1 affected package
rabbitmq-java-client
| Package | 24.04 LTS |
|---|---|
| rabbitmq-java-client | Needs evaluation |
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an...
1 affected package
rabbitmq-java-client
| Package | 24.04 LTS |
|---|---|
| rabbitmq-java-client | Needs evaluation |
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol()...
1 affected package
rabbitmq-java-client
| Package | 24.04 LTS |
|---|---|
| rabbitmq-java-client | Needs evaluation |
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java...
1 affected package
rabbitmq-java-client
| Package | 24.04 LTS |
|---|---|
| rabbitmq-java-client | Needs evaluation |