Search CVE reports
191 – 200 of 26733 results
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Needs evaluation |
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command...
1 affected package
jupyterlab
| Package | 26.04 LTS |
|---|---|
| jupyterlab | Needs evaluation |
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager...
1 affected package
jupyterlab
| Package | 26.04 LTS |
|---|---|
| jupyterlab | Needs evaluation |
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Needs evaluation |
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Needs evaluation |
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
1 affected package
csync2
| Package | 26.04 LTS |
|---|---|
| csync2 | Needs evaluation |
Not in release
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss...
1 affected package
mongodb
| Package | 26.04 LTS |
|---|---|
| mongodb | Not in release |
(SPIP versions prior to 4.4.14 contain a remote code execution vulnerab ...)
1 affected package
spip
| Package | 26.04 LTS |
|---|---|
| spip | Needs evaluation |
(Sandbox escape in the Profile Backup component. This vulnerability was ...)
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 26.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Not in release |
| mozjs115 | Not in release |