Search CVE reports
301 – 310 of 27411 results
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\d+(?:\.\d*)?"). When the...
2 affected packages
mistune, mistune0
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |
| mistune0 | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used as href="#<id>") and the text...
2 affected packages
mistune, mistune0
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |
| mistune0 | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTML — with no call to escape(),...
2 affected packages
mistune, mistune0
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |
| mistune0 | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes...
2 affected packages
mistune, mistune0
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |
| mistune0 | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied content directly into the HTML...
2 affected packages
mistune, mistune0
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |
| mistune0 | Needs evaluation |
Not in release
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory...
1 affected package
gpac
| Package | 26.04 LTS |
|---|---|
| gpac | Not in release |
FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer,...
1 affected package
fastnetmon
| Package | 26.04 LTS |
|---|---|
| fastnetmon | Needs evaluation |
Not in release
A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs...
1 affected package
gpac
| Package | 26.04 LTS |
|---|---|
| gpac | Not in release |
FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.
1 affected package
fastnetmon
| Package | 26.04 LTS |
|---|---|
| fastnetmon | Needs evaluation |
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs...
1 affected package
fastnetmon
| Package | 26.04 LTS |
|---|---|
| fastnetmon | Needs evaluation |