Search CVE reports
861 – 870 of 41636 results
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
1 affected package
wlc
| Package | 18.04 LTS |
|---|---|
| wlc | Fixed |
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2...
1 affected package
avahi
| Package | 18.04 LTS |
|---|---|
| avahi | Fixed |
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource...
1 affected package
avahi
| Package | 18.04 LTS |
|---|---|
| avahi | Fixed |
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record...
1 affected package
avahi
| Package | 18.04 LTS |
|---|---|
| avahi | Fixed |
A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results...
1 affected package
opencolorio
| Package | 18.04 LTS |
|---|---|
| opencolorio | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory...
1 affected package
python-virtualenv
| Package | 18.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...
1 affected package
python-filelock
| Package | 18.04 LTS |
|---|---|
| python-filelock | Fixed |
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc...
1 affected package
harfbuzz
| Package | 18.04 LTS |
|---|---|
| harfbuzz | Not affected |
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long...
2 affected packages
pypdf, pypdf2
| Package | 18.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF...
2 affected packages
pypdf, pypdf2
| Package | 18.04 LTS |
|---|---|
| pypdf | — |
| pypdf2 | Needs evaluation |