Search CVE reports
771 – 780 of 36839 results
(xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...)
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
(xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...)
1 affected package
node-xmldom
| Package | 26.04 LTS |
|---|---|
| node-xmldom | Needs evaluation |
(DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)
1 affected package
jackson-databind
| Package | 26.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public...
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |
With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the...
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Not affected |
(Net::DNS versions before 1.57 for Perl allow memory exhaustion via unb ...)
1 affected package
libnet-dns-perl
| Package | 26.04 LTS |
|---|---|
| libnet-dns-perl | Needs evaluation |
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then...
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Not affected |
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections...
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's...
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |