Search CVE reports
1 – 10 of 50 results
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through...
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox...
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags....
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input....
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files...
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y'...
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(NLTK before 3.10.3 contains a regular expression denial of service (Re ...)
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(NLTK versions before 3.10.0 contain a regular expression denial of ser ...)
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(NLTK versions before 3.10.3 contain a path traversal vulnerability in ...)
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
1 affected package
nltk
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nltk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |