Search CVE reports
1861 – 1870 of 47976 results
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in...
1 affected package
lxml
| Package | 20.04 LTS |
|---|---|
| lxml | Needs evaluation |
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against...
1 affected package
graphicsmagick
| Package | 20.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory,...
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read...
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size...
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the...
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP...
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory...
2 affected packages
libvirt, libvirt-hwe
| Package | 20.04 LTS |
|---|---|
| libvirt | Needs evaluation |
| libvirt-hwe | — |
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by...
2 affected packages
libsoup2.4, libsoup3
| Package | 20.04 LTS |
|---|---|
| libsoup2.4 | Needs evaluation |
| libsoup3 | — |
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 20.04 LTS |
|---|---|
| expat | Vulnerable |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | — |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | — |
| cableswig | — |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | — |
| smart | — |
| firefox | — |
| thunderbird | — |
| libxmltok | Needs evaluation |