Search CVE reports
361 – 370 of 34607 results
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py...
1 affected package
jupyterlab
| Package | 26.04 LTS |
|---|---|
| jupyterlab | Needs evaluation |
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest...
1 affected package
libdbi-perl
| Package | 26.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7...
1 affected package
libdbi-perl
| Package | 26.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can...
1 affected package
rust-actix-http
| Package | 26.04 LTS |
|---|---|
| rust-actix-http | Needs evaluation |
(Net::OAuth versions before 0.32 for Perl allow memory exhaustion via u ...)
1 affected package
libnet-oauth-perl
| Package | 26.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
(Net::OAuth::Client versions before 0.32 for Perl allow the service pro ...)
1 affected package
libnet-oauth-perl
| Package | 26.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating...
1 affected package
golang-github-go-chi-chi
| Package | 26.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites...
1 affected package
golang-github-go-chi-chi
| Package | 26.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based...
1 affected package
golang-github-go-chi-chi
| Package | 26.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
Not in release
The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path;...
1 affected package
rust-actix-files
| Package | 26.04 LTS |
|---|---|
| rust-actix-files | Not in release |