Search CVE reports
241 – 250 of 32962 results
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to...
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss()...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7...
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips...
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
1 affected package
bouncycastle
| Package | 26.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |