Search CVE reports
111 – 120 of 49291 results
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value...
1 affected package
libdbi-perl
| Package | 20.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...
2 affected packages
varnish, vinyl-cache
| Package | 20.04 LTS |
|---|---|
| varnish | Needs evaluation |
| vinyl-cache | — |
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against...
1 affected package
python-autobahn
| Package | 20.04 LTS |
|---|---|
| python-autobahn | Needs evaluation |
In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in theĀ at smpp34_unpack() function via attacker controlledĀ SMPP PDUs, leading to memory corruption.
1 affected package
libsmpp34
| Package | 20.04 LTS |
|---|---|
| libsmpp34 | Needs evaluation |
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set...
1 affected package
pg-partman
| Package | 20.04 LTS |
|---|---|
| pg-partman | Needs evaluation |
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept...
1 affected package
pg-partman
| Package | 20.04 LTS |
|---|---|
| pg-partman | Needs evaluation |
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without...
1 affected package
pg-partman
| Package | 20.04 LTS |
|---|---|
| pg-partman | Needs evaluation |
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place...
1 affected package
pg-partman
| Package | 20.04 LTS |
|---|---|
| pg-partman | Needs evaluation |