Search CVE reports
1261 – 1270 of 43788 results
Some fixes available 1 of 2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 24.04 LTS |
|---|---|
| freerdp | Not in release |
| freerdp2 | Needs evaluation |
| freerdp3 | Fixed |
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the...
1 affected package
ffuf
| Package | 24.04 LTS |
|---|---|
| ffuf | Needs evaluation |
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and...
1 affected package
djangorestframework
| Package | 24.04 LTS |
|---|---|
| djangorestframework | Needs evaluation |
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI...
1 affected package
flawfinder
| Package | 24.04 LTS |
|---|---|
| flawfinder | Needs evaluation |
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the...
1 affected package
python-socketio
| Package | 24.04 LTS |
|---|---|
| python-socketio | Needs evaluation |
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser...
1 affected package
djangorestframework
| Package | 24.04 LTS |
|---|---|
| djangorestframework | Needs evaluation |
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked...
1 affected package
python-engineio
| Package | 24.04 LTS |
|---|---|
| python-engineio | Needs evaluation |
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the...
1 affected package
python-engineio
| Package | 24.04 LTS |
|---|---|
| python-engineio | Needs evaluation |
Not in release
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |