Search CVE reports
11 – 20 of 34941 results
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
Some fixes available 1 of 2
Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
Some fixes available 1 of 2
QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
Some fixes available 1 of 2
CMP Indefinite Cache Growth of ExtraCerts
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
Some fixes available 1 of 2
Untrusted Sender DN Used as Format String in CMP Response Validation
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
Some fixes available 1 of 2
Heap Buffer Overflow in CMS Key Unwrapping
5 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |