Search CVE reports
1421 – 1430 of 48458 results
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys....
1 affected package
python-jwcrypto
| Package | 20.04 LTS |
|---|---|
| python-jwcrypto | Needs evaluation |
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries...
1 affected package
ruby-zip
| Package | 20.04 LTS |
|---|---|
| ruby-zip | Needs evaluation |
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid...
1 affected package
node-node-forge
| Package | 20.04 LTS |
|---|---|
| node-node-forge | Needs evaluation |
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the...
1 affected package
c-ares
| Package | 20.04 LTS |
|---|---|
| c-ares | Needs evaluation |
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...
1 affected package
php-mongodb
| Package | 20.04 LTS |
|---|---|
| php-mongodb | Needs evaluation |
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...
1 affected package
ntopng
| Package | 20.04 LTS |
|---|---|
| ntopng | Needs evaluation |
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...
1 affected package
mongo-c-driver
| Package | 20.04 LTS |
|---|---|
| mongo-c-driver | Needs evaluation |