Search CVE reports
731 – 740 of 26524 results
(ModSecurity is an open source, cross platform web application firewall ...)
1 affected package
modsecurity
| Package | 26.04 LTS |
|---|---|
| modsecurity | Needs evaluation |
(Redis is an in-memory data structure store. In redis-server from 7.2.0 ...)
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |
(Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in ...)
1 affected package
assimp
| Package | 26.04 LTS |
|---|---|
| assimp | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and...
1 affected package
jupyter-server
| Package | 26.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because...
1 affected package
jupyter-server
| Package | 26.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed...
1 affected package
proftpd-dfsg
| Package | 26.04 LTS |
|---|---|
| proftpd-dfsg | Needs evaluation |
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a...
1 affected package
horizon
| Package | 26.04 LTS |
|---|---|
| horizon | Needs evaluation |
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated...
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker...
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply...
1 affected package
redis
| Package | 26.04 LTS |
|---|---|
| redis | Needs evaluation |