Search CVE reports
251 – 260 of 40159 results
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...
1 affected package
node-axios
| Package | 26.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A...
1 affected package
node-axios
| Package | 26.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate...
1 affected package
node-axios
| Package | 26.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request...
1 affected package
node-axios
| Package | 26.04 LTS |
|---|---|
| node-axios | Needs evaluation |
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When...
1 affected package
libdbi-perl
| Package | 26.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without...
1 affected package
libdbi-perl
| Package | 26.04 LTS |
|---|---|
| libdbi-perl | Needs evaluation |
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...
1 affected package
libxs-parse-keyword-perl
| Package | 26.04 LTS |
|---|---|
| libxs-parse-keyword-perl | Needs evaluation |
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT...
1 affected package
nut
| Package | 26.04 LTS |
|---|---|
| nut | Needs evaluation |
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
Not in release
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An...
1 affected package
python-keycloak
| Package | 26.04 LTS |
|---|---|
| python-keycloak | Not in release |