Search CVE reports
391 – 400 of 27411 results
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...
7 affected packages
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...
| Package | 26.04 LTS |
|---|---|
| ruby2.3 | Not in release |
| ruby2.5 | Not in release |
| ruby2.7 | Not in release |
| ruby3.0 | Not in release |
| ruby3.2 | Not in release |
| ruby3.3 | Needs evaluation |
| jruby | Needs evaluation |
Not in release
In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model...
1 affected package
armnn
| Package | 26.04 LTS |
|---|---|
| armnn | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
Not in release
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
1 affected package
golang-golang-x-net-dev
| Package | 26.04 LTS |
|---|---|
| golang-golang-x-net-dev | Not in release |
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Needs evaluation |
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match...
1 affected package
node-shell-quote
| Package | 26.04 LTS |
|---|---|
| node-shell-quote | Needs evaluation |