Search CVE reports
341 – 350 of 53339 results
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs...
1 affected package
pyjwt
| Package | 22.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without...
1 affected package
python-authlib
| Package | 22.04 LTS |
|---|---|
| python-authlib | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable...
58 affected packages
gcc-3.3, gcc-4.6, gcc-4.7, gcc-4.8, gcc-4.9...
| Package | 22.04 LTS |
|---|---|
| gcc-3.3 | Needs evaluation |
| gcc-4.6 | Not in release |
| gcc-4.7 | Not in release |
| gcc-4.8 | Not in release |
| gcc-4.9 | Not in release |
| gcc-5 | Not in release |
| gcc-6 | Not in release |
| gcc-7 | Not in release |
| gcc-8 | Not in release |
| gcc-9 | Needs evaluation |
| gcc-10 | Needs evaluation |
| gcc-11 | Needs evaluation |
| gcc-12 | Needs evaluation |
| gcc-13 | Not in release |
| gcc-4.9-cross | Not in release |
| gcc-5-cross | Not in release |
| gcc-5-cross-ports | Not in release |
| gcc-6-cross | Not in release |
| gcc-6-cross-ports | Not in release |
| gcc-7-cross | Not in release |
| gcc-7-cross-ports | Not in release |
| gcc-8-cross | Not in release |
| gcc-8-cross-ports | Not in release |
| gcc-9-cross | Needs evaluation |
| gcc-9-cross-mipsen | Needs evaluation |
| gcc-9-cross-ports | Needs evaluation |
| gcc-10-cross | Needs evaluation |
| gcc-10-cross-mipsen | Needs evaluation |
| gcc-10-cross-ports | Needs evaluation |
| gcc-11-cross | Needs evaluation |
| gcc-11-cross-mipsen | Not in release |
| gcc-11-cross-ports | Needs evaluation |
| gcc-12-cross | Needs evaluation |
| gcc-12-cross-mipsen | Not in release |
| gcc-12-cross-ports | Needs evaluation |
| gcc-13-cross | Not in release |
| gcc-13-cross-ports | Not in release |
| gcc-or1k-elf | Needs evaluation |
| gcc-riscv64-unknown-elf | Needs evaluation |
| gcc-xtensa-lx106 | Needs evaluation |
| gcc-snapshot | Needs evaluation |
| gcc-i686-linux-android | Not in release |
| gcc-4.7-armel-cross | Not in release |
| gcc-4.7-armhf-cross | Not in release |
| gcc-4.8-arm64-cross | Not in release |
| gcc-4.8-armhf-cross | Not in release |
| gcc-4.8-powerpc-cross | Not in release |
| gcc-4.8-ppc64el-cross | Not in release |
| gcc-arm-linux-androideabi | Not in release |
| gcc-arm-none-eabi | Needs evaluation |
| gcc-avr | Needs evaluation |
| gcc-defaults | Needs evaluation |
| gcc-h8300-hms | Needs evaluation |
| gcc-m68hc1x | Needs evaluation |
| gcc-mingw-w64 | Needs evaluation |
| gcc-msp430 | Needs evaluation |
| gccgo-4.9 | Not in release |
| gccgo-6 | Not in release |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6...
1 affected package
node-ip-address
| Package | 22.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both...
1 affected package
node-ip-address
| Package | 22.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid...
1 affected package
node-ip-address
| Package | 22.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48....
1 affected package
node-ip-address
| Package | 22.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution....
1 affected package
node-axios
| Package | 22.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate...
1 affected package
node-axios
| Package | 22.04 LTS |
|---|---|
| node-axios | Needs evaluation |