Search CVE reports
541 – 550 of 45341 results
NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y'...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect...
1 affected package
rsyslog
| Package | 24.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through...
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the...
1 affected package
undertow
| Package | 24.04 LTS |
|---|---|
| undertow | Needs evaluation |
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 -...
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring...
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 -...
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
1 affected package
libspring-java
| Package | 24.04 LTS |
|---|---|
| libspring-java | Needs evaluation |