Search CVE reports
171 – 180 of 34920 results
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a...
1 affected package
lasso
| Package | 20.04 LTS |
|---|---|
| lasso | Needs evaluation |
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of...
1 affected package
lasso
| Package | 20.04 LTS |
|---|---|
| lasso | Needs evaluation |
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a...
1 affected package
lasso
| Package | 20.04 LTS |
|---|---|
| lasso | Needs evaluation |
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed...
1 affected package
lasso
| Package | 20.04 LTS |
|---|---|
| lasso | Needs evaluation |
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Not affected |
Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Not affected |
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use...
3 affected packages
runc, runc-app, runc-stable
| Package | 20.04 LTS |
|---|---|
| runc | Ignored |
| runc-app | Ignored |
| runc-stable | Not in release |
runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks...
3 affected packages
runc, runc-app, runc-stable
| Package | 20.04 LTS |
|---|---|
| runc | Ignored |
| runc-app | Ignored |
| runc-stable | Not in release |
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that...
3 affected packages
runc, runc-app, runc-stable
| Package | 20.04 LTS |
|---|---|
| runc | Ignored |
| runc-app | Ignored |
| runc-stable | Not in release |
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Fixed |