Search CVE reports
961 – 970 of 34564 results
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is...
1 affected package
ruby-loofah
| Package | 26.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...
1 affected package
ruby-loofah
| Package | 26.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the...
1 affected package
gst-plugins-good1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying...
1 affected package
gst-plugins-good1.0
| Package | 26.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based...
1 affected package
mkdocs-material
| Package | 26.04 LTS |
|---|---|
| mkdocs-material | Needs evaluation |
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
2 affected packages
openssh, openssh-ssh1
| Package | 26.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
2 affected packages
openssh, openssh-ssh1
| Package | 26.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...
2 affected packages
openssh, openssh-ssh1
| Package | 26.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip...
1 affected package
calibre
| Package | 26.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does...
1 affected package
calibre
| Package | 26.04 LTS |
|---|---|
| calibre | Needs evaluation |