Search CVE reports
71 – 80 of 35004 results
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file://...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
Some fixes available 1 of 3
Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Needs evaluation |
Some fixes available 1 of 3
QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Needs evaluation |
Some fixes available 1 of 3
CMP Indefinite Cache Growth of ExtraCerts
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Needs evaluation |
Some fixes available 1 of 3
Untrusted Sender DN Used as Format String in CMP Response Validation
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Needs evaluation |
Some fixes available 1 of 3
Heap Buffer Overflow in CMS Key Unwrapping
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Needs evaluation |
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |