Search CVE reports
981 – 990 of 47438 results
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails...
1 affected package
rclone
| Package | 20.04 LTS |
|---|---|
| rclone | Needs evaluation |
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature...
1 affected package
ruby-nokogiri
| Package | 20.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to...
1 affected package
ruby-nokogiri
| Package | 20.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into...
1 affected package
ruby-nokogiri
| Package | 20.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode...
1 affected package
ruby-nokogiri
| Package | 20.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath,...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas....
1 affected package
ruby-nokogiri
| Package | 20.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |