Search CVE reports
691 – 700 of 33680 results
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens...
1 affected package
pypdf
| Package | 26.04 LTS |
|---|---|
| pypdf | Needs evaluation |
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet...
1 affected package
golang-github-gopacket-gopacket
| Package | 26.04 LTS |
|---|---|
| golang-github-gopacket-gopacket | Needs evaluation |
Not in release
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |
Not in release
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 26.04 LTS |
|---|---|
| consul | Not in release |