Search CVE reports
761 – 770 of 26527 results
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory...
1 affected package
python-django
| Package | 26.04 LTS |
|---|---|
| python-django | Fixed |
Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
1 affected package
python-django
| Package | 26.04 LTS |
|---|---|
| python-django | Fixed |
Not in release
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
1 affected package
eclipse
| Package | 26.04 LTS |
|---|---|
| eclipse | Not in release |
Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the...
1 affected package
eclipse-equinox
| Package | 26.04 LTS |
|---|---|
| eclipse-equinox | Needs evaluation |
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality....
1 affected package
eclipse-equinox
| Package | 26.04 LTS |
|---|---|
| eclipse-equinox | Needs evaluation |
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a...
1 affected package
node-ajv
| Package | 26.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled...
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
1 affected package
thrift
| Package | 26.04 LTS |
|---|---|
| thrift | Needs evaluation |
An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated...
1 affected package
nix
| Package | 26.04 LTS |
|---|---|
| nix | Needs evaluation |