Search CVE reports
761 – 770 of 59380 results
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns,...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
1 affected package
xiphos
| Package | 16.04 LTS |
|---|---|
| xiphos | Needs evaluation |
web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).
1 affected package
web2py
| Package | 16.04 LTS |
|---|---|
| web2py | Needs evaluation |
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...
1 affected package
libemail-sender-perl
| Package | 16.04 LTS |
|---|---|
| libemail-sender-perl | Needs evaluation |