Search CVE reports
981 – 990 of 55619 results
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method....
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
[GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-624p-cp8x-6hp6: EchoLink RTCP/SDES: out-of-bounds read]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |
[GHSA-6wgq-wg3w-jgvx: svxreflector: use-after-free write via dangling JSON reference]
1 affected package
svxlink
| Package | 16.04 LTS |
|---|---|
| svxlink | Needs evaluation |