Search CVE reports
221 – 230 of 49410 results
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted...
1 affected package
python-virtualenv
| Package | 24.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
Not in release
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches...
1 affected package
jupyterlab
| Package | 24.04 LTS |
|---|---|
| jupyterlab | Not in release |
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be...
1 affected package
poppler
| Package | 24.04 LTS |
|---|---|
| poppler | Needs evaluation |
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted...
1 affected package
iperf3
| Package | 24.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
Not in release
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response...
1 affected package
ruby-llm
| Package | 24.04 LTS |
|---|---|
| ruby-llm | Not in release |
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to...
1 affected package
vlc
| Package | 24.04 LTS |
|---|---|
| vlc | Needs evaluation |
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite...
2 affected packages
jupyter-notebook, jupyterlab
| Package | 24.04 LTS |
|---|---|
| jupyter-notebook | Needs evaluation |
| jupyterlab | Not in release |
Not in release
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the...
1 affected package
jupyterlab
| Package | 24.04 LTS |
|---|---|
| jupyterlab | Not in release |
Not in release
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with...
1 affected package
rust-russh
| Package | 24.04 LTS |
|---|---|
| rust-russh | Not in release |
Not in release
Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh...
1 affected package
rust-russh
| Package | 24.04 LTS |
|---|---|
| rust-russh | Not in release |