Search CVE reports


Toggle filters

11 – 20 of 25 results


CVE-2022-4396

Medium priority
Vulnerable

A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be...

3 affected packages

py, python-pyrdfa, rdflib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py Not in release Not in release Not in release
python-pyrdfa Not affected Not affected Vulnerable Not in release Not in release
rdflib Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-42969

Medium priority
Ignored

The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument...

2 affected packages

py, python-py

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py Not in release Not in release Not in release Not in release
python-py Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-41499

Medium priority
Needs evaluation

Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remote attackers to conduct DoS attacks by deliberately passing on an overlong audio file name.

1 affected package

python-pyo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pyo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-41498

Medium priority
Needs evaluation

Buffer overflow in ajaxsoundstudio.com Pyo &lt and 1.03 in the Server_jack_init function. which allows attackers to conduct Denial of Service attacks by arbitrary constructing a overlong server name.

1 affected package

python-pyo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pyo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-21239

Medium priority

Some fixes available 6 of 7

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and...

1 affected package

python-pysaml2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Fixed Fixed Fixed
Show less packages

CVE-2021-21238

Low priority
Vulnerable

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are...

1 affected package

python-pysaml2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-29651

Medium priority

Some fixes available 2 of 3

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame...

1 affected package

python-py

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-py Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-5390

Medium priority
Fixed

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object...

1 affected package

python-pysaml2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Fixed
Show less packages

CVE-2018-1000872

Medium priority
Needs evaluation

OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or...

1 affected package

python-pykmip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pykmip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-1000433

Medium priority
Fixed

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

1 affected package

python-pysaml2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2
Show less packages