Search CVE reports
31 – 40 of 50365 results
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed...
1 affected package
poppler
| Package | 20.04 LTS |
|---|---|
| poppler | Needs evaluation |
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention...
1 affected package
barman
| Package | 20.04 LTS |
|---|---|
| barman | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with...
1 affected package
python-virtualenv
| Package | 20.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker...
1 affected package
python-virtualenv
| Package | 20.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes...
1 affected package
python-virtualenv
| Package | 20.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted...
1 affected package
python-virtualenv
| Package | 20.04 LTS |
|---|---|
| python-virtualenv | Needs evaluation |
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be...
1 affected package
poppler
| Package | 20.04 LTS |
|---|---|
| poppler | Needs evaluation |
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted...
1 affected package
iperf3
| Package | 20.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to...
1 affected package
vlc
| Package | 20.04 LTS |
|---|---|
| vlc | Needs evaluation |
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite...
2 affected packages
jupyter-notebook, jupyterlab
| Package | 20.04 LTS |
|---|---|
| jupyter-notebook | Needs evaluation |
| jupyterlab | — |