Search CVE reports
1 – 10 of 913 results
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several...
2 affected packages
commonmark, markdown
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| commonmark | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
| markdown | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab,...
2 affected packages
commonmark, markdown
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| commonmark | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
| markdown | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups...
12 affected packages
markdown, python2.7, python3.4, python3.5, python3.6...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| markdown | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python2.7 | Not in release | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
| python3.4 | Not in release | Not in release | Not in release | — | — |
| python3.5 | Not in release | Not in release | Not in release | — | — |
| python3.6 | Not in release | Not in release | Not in release | — | Needs evaluation |
| python3.7 | Not in release | Not in release | Not in release | — | Needs evaluation |
| python3.8 | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
| python3.9 | Not in release | Not in release | Not in release | Needs evaluation | — |
| python3.10 | Not in release | Not in release | Needs evaluation | — | — |
| python3.11 | Not in release | Not in release | Needs evaluation | — | — |
| python3.12 | Not in release | Needs evaluation | Not in release | — | — |
| python3.14 | Needs evaluation | Not in release | Not in release | — | — |
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...
2 affected packages
markdown, python-markdown
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| markdown | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-markdown | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
8 affected packages
libraw, ufraw, darktable, exactimage, dcraw...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libraw | Not affected | Not affected | Not affected | Not affected | Not affected |
| ufraw | Not in release | Not in release | Not in release | — | Not affected |
| darktable | Not affected | Not affected | Not affected | Not affected | Not affected |
| exactimage | Not affected | Not affected | Not affected | Not affected | Not affected |
| dcraw | Not affected | Not affected | Not affected | Not affected | Not affected |
| rawtherapee | Not affected | Not affected | Not affected | Not affected | Not affected |
| kodi | Not affected | Not affected | Not affected | Not affected | Not affected |
| digikam | Not affected | Not affected | Not affected | Not affected | Not affected |
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails...
1 affected package
node-markdown-it
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| node-markdown-it | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
1 affected package
wireshark
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| wireshark | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
1 affected package
wireshark
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| wireshark | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
1 affected package
wireshark
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| wireshark | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
1 affected package
wireshark
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| wireshark | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |