Search CVE reports
721 – 730 of 33037 results
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2....
2 affected packages
pypdf, pypdf2
| Package | 24.04 LTS |
|---|---|
| pypdf | Needs evaluation |
| pypdf2 | Needs evaluation |
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal....
1 affected package
node-rollup
| Package | 24.04 LTS |
|---|---|
| node-rollup | Needs evaluation |
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the...
1 affected package
rust-wasmtime
| Package | 24.04 LTS |
|---|---|
| rust-wasmtime | Needs evaluation |
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime...
1 affected package
rust-wasmtime
| Package | 24.04 LTS |
|---|---|
| rust-wasmtime | Needs evaluation |
Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling...
1 affected package
rust-wasmtime
| Package | 24.04 LTS |
|---|---|
| rust-wasmtime | Not affected |
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to...
1 affected package
caddy
| Package | 24.04 LTS |
|---|---|
| caddy | Needs evaluation |
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running...
1 affected package
caddy
| Package | 24.04 LTS |
|---|---|
| caddy | Needs evaluation |
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes...
1 affected package
caddy
| Package | 24.04 LTS |
|---|---|
| caddy | Needs evaluation |
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`)...
1 affected package
caddy
| Package | 24.04 LTS |
|---|---|
| caddy | Needs evaluation |
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA...
1 affected package
caddy
| Package | 24.04 LTS |
|---|---|
| caddy | Needs evaluation |