Search CVE reports
531 – 540 of 39399 results
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM...
1 affected package
radare2
| Package | 26.04 LTS |
|---|---|
| radare2 | Needs evaluation |
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length...
1 affected package
radare2
| Package | 26.04 LTS |
|---|---|
| radare2 | Needs evaluation |
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no...
1 affected package
webpy
| Package | 26.04 LTS |
|---|---|
| webpy | Needs evaluation |
webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().
1 affected package
webpy
| Package | 26.04 LTS |
|---|---|
| webpy | Needs evaluation |
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard...
1 affected package
python-anyio
| Package | 26.04 LTS |
|---|---|
| python-anyio | Needs evaluation |
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0,...
1 affected package
jackson-core
| Package | 26.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result,...
1 affected package
webpy
| Package | 26.04 LTS |
|---|---|
| webpy | Needs evaluation |
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory...
58 affected packages
gcc-3.3, gcc-4.6, gcc-4.7, gcc-4.8, gcc-4.9...
| Package | 26.04 LTS |
|---|---|
| gcc-3.3 | Not in release |
| gcc-4.6 | Not in release |
| gcc-4.7 | Not in release |
| gcc-4.8 | Not in release |
| gcc-4.9 | Not in release |
| gcc-5 | Not in release |
| gcc-6 | Not in release |
| gcc-7 | Not in release |
| gcc-8 | Not in release |
| gcc-9 | Not in release |
| gcc-10 | Not in release |
| gcc-11 | Needs evaluation |
| gcc-12 | Needs evaluation |
| gcc-13 | Needs evaluation |
| gcc-4.9-cross | Not in release |
| gcc-5-cross | Not in release |
| gcc-5-cross-ports | Not in release |
| gcc-6-cross | Not in release |
| gcc-6-cross-ports | Not in release |
| gcc-7-cross | Not in release |
| gcc-7-cross-ports | Not in release |
| gcc-8-cross | Not in release |
| gcc-8-cross-ports | Not in release |
| gcc-9-cross | Not in release |
| gcc-9-cross-mipsen | Not in release |
| gcc-9-cross-ports | Not in release |
| gcc-10-cross | Not in release |
| gcc-10-cross-mipsen | Not in release |
| gcc-10-cross-ports | Not in release |
| gcc-11-cross | Needs evaluation |
| gcc-11-cross-mipsen | Not in release |
| gcc-11-cross-ports | Needs evaluation |
| gcc-12-cross | Needs evaluation |
| gcc-12-cross-mipsen | Not in release |
| gcc-12-cross-ports | Needs evaluation |
| gcc-13-cross | Needs evaluation |
| gcc-13-cross-ports | Needs evaluation |
| gcc-or1k-elf | Needs evaluation |
| gcc-riscv64-unknown-elf | Needs evaluation |
| gcc-xtensa-lx106 | Not in release |
| gcc-snapshot | Needs evaluation |
| gcc-i686-linux-android | Not in release |
| gcc-4.7-armel-cross | Not in release |
| gcc-4.7-armhf-cross | Not in release |
| gcc-4.8-arm64-cross | Not in release |
| gcc-4.8-armhf-cross | Not in release |
| gcc-4.8-powerpc-cross | Not in release |
| gcc-4.8-ppc64el-cross | Not in release |
| gcc-arm-linux-androideabi | Not in release |
| gcc-arm-none-eabi | Needs evaluation |
| gcc-avr | Needs evaluation |
| gcc-defaults | Needs evaluation |
| gcc-h8300-hms | Needs evaluation |
| gcc-m68hc1x | Not in release |
| gcc-mingw-w64 | Needs evaluation |
| gcc-msp430 | Not in release |
| gccgo-4.9 | Not in release |
| gccgo-6 | Not in release |
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked...
1 affected package
libreoffice
| Package | 26.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...
1 affected package
libreoffice
| Package | 26.04 LTS |
|---|---|
| libreoffice | Needs evaluation |