Search CVE reports
11 – 20 of 58632 results
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text,...
1 affected package
libdancer2-perl
| Package | 16.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...
1 affected package
libemail-sender-perl
| Package | 16.04 LTS |
|---|---|
| libemail-sender-perl | Needs evaluation |
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
1 affected package
libxrender
| Package | 16.04 LTS |
|---|---|
| libxrender | Needs evaluation |
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
1 affected package
libx11
| Package | 16.04 LTS |
|---|---|
| libx11 | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |