Search CVE reports
131 – 140 of 36262 results
The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...
1 affected package
erlang
| Package | 26.04 LTS |
|---|---|
| erlang | Needs evaluation |
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...
1 affected package
freeipa
| Package | 26.04 LTS |
|---|---|
| freeipa | Needs evaluation |
Not in release
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...
1 affected package
dogtag-pki
| Package | 26.04 LTS |
|---|---|
| dogtag-pki | Not in release |
Not in release
async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g...
1 affected package
rust-async-tar
| Package | 26.04 LTS |
|---|---|
| rust-async-tar | Not in release |
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration...
2 affected packages
resteasy, resteasy3.0
| Package | 26.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
(The values of the mail.allowed_attachment_hostnames advanced config se ...)
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |
(A malicious IMAP server can trigger use-after-free and heap-memory dis ...)
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |
(A maliciously constructed mail header could lead to a one byte read pa ...)
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |
(Triggering an error condition in certain MIME bodies would cause unini ...)
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |
(Malicious calendar invitations could use file URI attachments to launc ...)
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |