Search CVE reports
1281 – 1290 of 47438 results
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities....
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active...
1 affected package
capstone
| Package | 20.04 LTS |
|---|---|
| capstone | Needs evaluation |
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without...
1 affected package
capstone
| Package | 20.04 LTS |
|---|---|
| capstone | Needs evaluation |
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and...
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which ...
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is...
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to...
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an...
1 affected package
tor
| Package | 20.04 LTS |
|---|---|
| tor | Needs evaluation |