Search CVE reports
81 – 90 of 33696 results
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 26.04 LTS |
|---|---|
| postgresql-18 | Needs evaluation |
| postgresql-16 | Not in release |
| postgresql-14 | Not in release |
| postgresql-12 | Not in release |
| postgresql-10 | Not in release |
| postgresql-9.5 | Not in release |
| postgresql-9.3 | Not in release |
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 26.04 LTS |
|---|---|
| postgresql-18 | Needs evaluation |
| postgresql-16 | Not in release |
| postgresql-14 | Not in release |
| postgresql-12 | Not in release |
| postgresql-10 | Not in release |
| postgresql-9.5 | Not in release |
| postgresql-9.3 | Not in release |
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 26.04 LTS |
|---|---|
| postgresql-18 | Needs evaluation |
| postgresql-16 | Not in release |
| postgresql-14 | Not in release |
| postgresql-12 | Not in release |
| postgresql-10 | Not in release |
| postgresql-9.5 | Not in release |
| postgresql-9.3 | Not in release |
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Needs evaluation |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
(HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)
1 affected package
libhtml-formhandler-perl
| Package | 26.04 LTS |
|---|---|
| libhtml-formhandler-perl | Needs evaluation |
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which...
1 affected package
python-tablib
| Package | 26.04 LTS |
|---|---|
| python-tablib | Needs evaluation |
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil...
1 affected package
golang-github-getkin-kin-openapi
| Package | 26.04 LTS |
|---|---|
| golang-github-getkin-kin-openapi | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...
1 affected package
etcd
| Package | 26.04 LTS |
|---|---|
| etcd | Needs evaluation |