Search CVE reports
1421 – 1430 of 37501 results
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify...
1 affected package
gvfs
| Package | 26.04 LTS |
|---|---|
| gvfs | Needs evaluation |
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify...
1 affected package
gvfs
| Package | 26.04 LTS |
|---|---|
| gvfs | Needs evaluation |
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled,...
1 affected package
gvfs
| Package | 26.04 LTS |
|---|---|
| gvfs | Needs evaluation |
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during...
1 affected package
rpm
| Package | 26.04 LTS |
|---|---|
| rpm | Needs evaluation |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Not affected |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic...
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |