Search CVE reports
21 – 30 of 29028 results
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
1 affected package
wireshark
Package | 24.04 LTS |
---|---|
wireshark | Needs evaluation |
Not in release
[Unknown description]
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could...
1 affected package
social-auth-app-django
Package | 24.04 LTS |
---|---|
social-auth-app-django | Needs evaluation |
[net/mail: excessive CPU consumption in ParseAddress]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |
[net/textproto: excessive CPU consumption in Reader.ReadResponse]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |
[encoding/pem: quadratic complexity when parsing some invalid inputs]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |
python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and...
1 affected package
python-jose
Package | 24.04 LTS |
---|---|
python-jose | Needs evaluation |
[crypto/tls: ALPN negotiation errors can contain arbitrary text]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |
[crypto/x509: panic when validating certificates with DSA public keys]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |
[crypto/x509: quadratic complexity when checking name constraints]
16 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS |
---|---|
golang | Not in release |
golang-1.6 | Not in release |
golang-1.8 | Not in release |
golang-1.9 | Not in release |
golang-1.10 | Not in release |
golang-1.13 | Not in release |
golang-1.14 | Not in release |
golang-1.16 | Not in release |
golang-1.17 | Not in release |
golang-1.18 | Not in release |
golang-1.20 | Not in release |
golang-1.21 | Needs evaluation |
golang-1.22 | Needs evaluation |
golang-1.23 | Needs evaluation |
golang-1.24 | Not in release |
golang-1.25 | Not in release |