Search CVE reports
381 – 390 of 37432 results
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
golang-mongodb-mongo-driver
| Package | 26.04 LTS |
|---|---|
| golang-mongodb-mongo-driver | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
ruby-mongo
| Package | 26.04 LTS |
|---|---|
| ruby-mongo | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
pymongo
| Package | 26.04 LTS |
|---|---|
| pymongo | Needs evaluation |
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...
12 affected packages
pypy3, python2.7, python3.4, python3.5, python3.6...
| Package | 26.04 LTS |
|---|---|
| pypy3 | Needs evaluation |
| python2.7 | Not in release |
| python3.4 | Not in release |
| python3.5 | Not in release |
| python3.6 | Not in release |
| python3.7 | Not in release |
| python3.8 | Not in release |
| python3.9 | Not in release |
| python3.10 | Not in release |
| python3.11 | Not in release |
| python3.12 | Not in release |
| python3.14 | Needs evaluation |
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...
1 affected package
node-multiparty
| Package | 26.04 LTS |
|---|---|
| node-multiparty | Needs evaluation |
morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that...
1 affected package
node-morgan
| Package | 26.04 LTS |
|---|---|
| node-morgan | Needs evaluation |
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...
1 affected package
node-compression
| Package | 26.04 LTS |
|---|---|
| node-compression | Needs evaluation |
Not in release
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
1 affected package
orthanc
| Package | 26.04 LTS |
|---|---|
| orthanc | Needs evaluation |
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...
1 affected package
keepass2
| Package | 26.04 LTS |
|---|---|
| keepass2 | Needs evaluation |