Search CVE reports
911 – 920 of 56955 results
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath,...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths...
1 affected package
nltk
| Package | 16.04 LTS |
|---|---|
| nltk | Needs evaluation |
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas....
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader....
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact...
1 affected package
ruby-nokogiri
| Package | 16.04 LTS |
|---|---|
| ruby-nokogiri | Needs evaluation |