Search CVE reports
61 – 70 of 50681 results
PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a...
1 affected package
pymupdf
| Package | 22.04 LTS |
|---|---|
| pymupdf | Needs evaluation |
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and...
1 affected package
allure
| Package | 22.04 LTS |
|---|---|
| allure | Needs evaluation |
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer()...
1 affected package
allure
| Package | 22.04 LTS |
|---|---|
| allure | Needs evaluation |
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine...
3 affected packages
containerd, containerd-app, containerd-stable
| Package | 22.04 LTS |
|---|---|
| containerd | Needs evaluation |
| containerd-app | Needs evaluation |
| containerd-stable | Not in release |
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed...
1 affected package
weasyprint
| Package | 22.04 LTS |
|---|---|
| weasyprint | Needs evaluation |
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply...
1 affected package
glance
| Package | 22.04 LTS |
|---|---|
| glance | Needs evaluation |
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
1 affected package
mbedtls
| Package | 22.04 LTS |
|---|---|
| mbedtls | Needs evaluation |
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
1 affected package
hoteldruid
| Package | 22.04 LTS |
|---|---|
| hoteldruid | Needs evaluation |
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
1 affected package
sgt-puzzles
| Package | 22.04 LTS |
|---|---|
| sgt-puzzles | Needs evaluation |
An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
1 affected package
sgt-puzzles
| Package | 22.04 LTS |
|---|---|
| sgt-puzzles | Needs evaluation |