Search CVE reports
11 – 20 of 58627 results
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...
1 affected package
ntopng
| Package | 16.04 LTS |
|---|---|
| ntopng | Needs evaluation |
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...
1 affected package
dogtag-pki
| Package | 16.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).
1 affected package
web2py
| Package | 16.04 LTS |
|---|---|
| web2py | Needs evaluation |