Search CVE reports
71 – 80 of 46861 results
(HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)
1 affected package
libhtml-formhandler-perl
| Package | 22.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which...
1 affected package
python-tablib
| Package | 22.04 LTS |
|---|---|
| python-tablib | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil...
1 affected package
golang-github-getkin-kin-openapi
| Package | 22.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...
1 affected package
etcd
| Package | 22.04 LTS |
|---|---|
| etcd | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey()...
1 affected package
etcd
| Package | 22.04 LTS |
|---|---|
| etcd | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs...
1 affected package
ruby-loofah
| Package | 22.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is...
1 affected package
ruby-loofah
| Package | 22.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...
1 affected package
ruby-loofah
| Package | 22.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the...
1 affected package
gst-plugins-good1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying...
1 affected package
gst-plugins-good1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |