Search CVE reports
271 – 280 of 44612 results
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups...
12 affected packages
markdown, python2.7, python3.4, python3.5, python3.6...
| Package | 20.04 LTS |
|---|---|
| markdown | Needs evaluation |
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | — |
| python3.6 | — |
| python3.7 | — |
| python3.8 | Needs evaluation |
| python3.9 | Needs evaluation |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...
1 affected package
anki
| Package | 20.04 LTS |
|---|---|
| anki | Needs evaluation |
[Unknown description]
1 affected package
wordpress
| Package | 20.04 LTS |
|---|---|
| wordpress | Needs evaluation |
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...
1 affected package
libvirt
| Package | 20.04 LTS |
|---|---|
| libvirt | Needs evaluation |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 20.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
| pdns | Needs evaluation |
| pdns-recursor | Needs evaluation |
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...
1 affected package
policycoreutils
| Package | 20.04 LTS |
|---|---|
| policycoreutils | Needs evaluation |
A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to...
1 affected package
p11-kit
| Package | 20.04 LTS |
|---|---|
| p11-kit | Needs evaluation |
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead...
1 affected package
nltk
| Package | 20.04 LTS |
|---|---|
| nltk | Needs evaluation |
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...
2 affected packages
markdown, python-markdown
| Package | 20.04 LTS |
|---|---|
| markdown | Needs evaluation |
| python-markdown | Needs evaluation |
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon...
1 affected package
epiphany-browser
| Package | 20.04 LTS |
|---|---|
| epiphany-browser | Needs evaluation |