Search CVE reports
201 – 210 of 50365 results
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs...
1 affected package
pyjwt
| Package | 20.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable...
58 affected packages
gcc-3.3, gcc-4.6, gcc-4.7, gcc-4.8, gcc-4.9...
| Package | 20.04 LTS |
|---|---|
| gcc-3.3 | Needs evaluation |
| gcc-4.6 | — |
| gcc-4.7 | — |
| gcc-4.8 | — |
| gcc-4.9 | — |
| gcc-5 | — |
| gcc-6 | — |
| gcc-7 | Needs evaluation |
| gcc-8 | Needs evaluation |
| gcc-9 | Needs evaluation |
| gcc-10 | Needs evaluation |
| gcc-11 | — |
| gcc-12 | — |
| gcc-13 | — |
| gcc-4.9-cross | — |
| gcc-5-cross | — |
| gcc-5-cross-ports | — |
| gcc-6-cross | — |
| gcc-6-cross-ports | — |
| gcc-7-cross | — |
| gcc-7-cross-ports | — |
| gcc-8-cross | Needs evaluation |
| gcc-8-cross-ports | Needs evaluation |
| gcc-9-cross | Needs evaluation |
| gcc-9-cross-mipsen | Needs evaluation |
| gcc-9-cross-ports | Needs evaluation |
| gcc-10-cross | Needs evaluation |
| gcc-10-cross-mipsen | Needs evaluation |
| gcc-10-cross-ports | Needs evaluation |
| gcc-11-cross | — |
| gcc-11-cross-mipsen | — |
| gcc-11-cross-ports | — |
| gcc-12-cross | — |
| gcc-12-cross-mipsen | — |
| gcc-12-cross-ports | — |
| gcc-13-cross | — |
| gcc-13-cross-ports | — |
| gcc-or1k-elf | — |
| gcc-riscv64-unknown-elf | Needs evaluation |
| gcc-xtensa-lx106 | Needs evaluation |
| gcc-snapshot | Needs evaluation |
| gcc-i686-linux-android | — |
| gcc-4.7-armel-cross | — |
| gcc-4.7-armhf-cross | — |
| gcc-4.8-arm64-cross | — |
| gcc-4.8-armhf-cross | — |
| gcc-4.8-powerpc-cross | — |
| gcc-4.8-ppc64el-cross | — |
| gcc-arm-linux-androideabi | — |
| gcc-arm-none-eabi | Needs evaluation |
| gcc-avr | Needs evaluation |
| gcc-defaults | Needs evaluation |
| gcc-h8300-hms | Needs evaluation |
| gcc-m68hc1x | Needs evaluation |
| gcc-mingw-w64 | Needs evaluation |
| gcc-msp430 | Needs evaluation |
| gccgo-4.9 | — |
| gccgo-6 | — |