Search CVE reports
1 – 10 of 39921 results
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for...
1 affected package
django-allauth
| Package | 18.04 LTS |
|---|---|
| django-allauth | Needs evaluation |
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
1 affected package
django-allauth
| Package | 18.04 LTS |
|---|---|
| django-allauth | Needs evaluation |
[avoid that non-admin user using other users' certificates]
1 affected package
network-manager
| Package | 18.04 LTS |
|---|---|
| network-manager | Needs evaluation |
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
1 affected package
uriparser
| Package | 18.04 LTS |
|---|---|
| uriparser | Needs evaluation |
Exim before 4.99.1 allows remote heap corruption that will be further described on 2025-12-18.
1 affected package
exim4
| Package | 18.04 LTS |
|---|---|
| exim4 | Not affected |
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted...
1 affected package
pcsx2
| Package | 18.04 LTS |
|---|---|
| pcsx2 | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in...
1 affected package
python-tornado
| Package | 18.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add...
1 affected package
python-tornado
| Package | 18.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the...
1 affected package
python-tornado
| Package | 18.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
(HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XS ...)
1 affected package
hoteldruid
| Package | 18.04 LTS |
|---|---|
| hoteldruid | Needs evaluation |