Search CVE reports
781 – 790 of 45011 results
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates,...
1 affected package
python-cryptography
| Package | 20.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a...
1 affected package
python-cryptography
| Package | 20.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a...
1 affected package
python-cryptography
| Package | 20.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker...
1 affected package
python-aiohttp
| Package | 20.04 LTS |
|---|---|
| python-aiohttp | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an...
1 affected package
python-aiohttp
| Package | 20.04 LTS |
|---|---|
| python-aiohttp | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the...
1 affected package
node-ip-address
| Package | 20.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser,...
1 affected package
node-ip-address
| Package | 20.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer...
1 affected package
node-socket.io-parser
| Package | 20.04 LTS |
|---|---|
| node-socket.io-parser | Needs evaluation |
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an...
1 affected package
node-postcss
| Package | 20.04 LTS |
|---|---|
| node-postcss | Needs evaluation |
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or...
1 affected package
node-brace-expansion
| Package | 20.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |