Search CVE reports
101 – 110 of 44358 results
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
1 affected package
vim
| Package | 20.04 LTS |
|---|---|
| vim | Needs evaluation |
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
1 affected package
vim
| Package | 20.04 LTS |
|---|---|
| vim | Needs evaluation |
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted...
1 affected package
sssd
| Package | 20.04 LTS |
|---|---|
| sssd | Needs evaluation |
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**,...
1 affected package
nodejs
| Package | 20.04 LTS |
|---|---|
| nodejs | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor....
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired...
1 affected package
jackson-core
| Package | 20.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses...
1 affected package
jackson-core
| Package | 20.04 LTS |
|---|---|
| jackson-core | Needs evaluation |