Search CVE reports
401 – 410 of 56196 results
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a...
1 affected package
openexr
| Package | 16.04 LTS |
|---|---|
| openexr | Needs evaluation |
Some fixes available 1 of 3
Excessive Memory Use Buffering DTLS Records for a Future Epoch
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 16.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Needs evaluation |
| edk2 | Needs evaluation |
| edk2-hwe | — |