Search CVE reports
221 – 230 of 56449 results
(An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code ...)
2 affected packages
znuny, otrs2
| Package | 16.04 LTS |
|---|---|
| znuny | — |
| otrs2 | Needs evaluation |
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader....
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
imap-login crash: Self-recursion on zero-output decompress chunks. An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash.
1 affected package
dovecot
| Package | 16.04 LTS |
|---|---|
| dovecot | Needs evaluation |
auth: db-oauth2: aud claim used as fallback for missing scope claim. An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the...
1 affected package
dovecot
| Package | 16.04 LTS |
|---|---|
| dovecot | Needs evaluation |