Search CVE reports


Toggle filters

281 – 290 of 829 results


CVE-2024-27351

Medium priority

Some fixes available 9 of 11

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression...

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-1892

Medium priority

Some fixes available 3 of 4

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient...

1 affected package

python-scrapy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-scrapy Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-27099

Medium priority
Needs evaluation

The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with...

1 affected package

azure-uamqp-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
azure-uamqp-python Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
Show less packages

CVE-2024-27454

Medium priority

Not in release

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

1 affected package

python-orjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-orjson Not in release Not in release Not in release
Show less packages

CVE-2024-26130

Medium priority
Fixed

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a...

1 affected package

python-cryptography

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-cryptography Fixed Not affected Not affected Not affected
Show less packages

CVE-2023-6110

Medium priority

Some fixes available 2 of 4

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

1 affected package

python-openstackclient

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-openstackclient Not affected Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2024-25110

Medium priority
Needs evaluation

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may...

1 affected package

azure-uamqp-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
azure-uamqp-python Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
Show less packages

CVE-2023-6681

Medium priority
Vulnerable

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large...

1 affected package

python-jwcrypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-jwcrypto Vulnerable Vulnerable Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-24680

Medium priority

Some fixes available 4 of 6

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-50782

Medium priority

Some fixes available 5 of 6

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

1 affected package

python-cryptography

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-cryptography Not affected Fixed Fixed Fixed
Show less packages