Search CVE reports
621 – 630 of 46580 results
Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
golang-mongodb-mongo-driver
| Package | 24.04 LTS |
|---|---|
| golang-mongodb-mongo-driver | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
ruby-mongo
| Package | 24.04 LTS |
|---|---|
| ruby-mongo | Needs evaluation |
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...
1 affected package
pymongo
| Package | 24.04 LTS |
|---|---|
| pymongo | Needs evaluation |
An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file
1 affected package
puma
| Package | 24.04 LTS |
|---|---|
| puma | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...
1 affected package
tesseract
| Package | 24.04 LTS |
|---|---|
| tesseract | Needs evaluation |