Search CVE reports


Toggle filters

341 – 350 of 471 results


CVE-2013-1739

Medium priority

Some fixes available 13 of 15

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified...

3 affected packages

firefox, nss, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
nss
thunderbird
Show less packages

CVE-2007-6755

Low priority
Ignored

The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might...

10 affected packages

openssl, mbedtls, openssl098, bouncycastle, gnutls26...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Not affected
mbedtls Not affected
openssl098 Not in release
bouncycastle Not affected
gnutls26 Not in release
gnutls28 Not affected
libgcrypt11 Not in release
nss Not affected
polarssl Not in release
python-crypto Not affected
Show all 10 packages Show less packages

CVE-2013-4314

Medium priority
Fixed

The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL...

1 affected package

pyopenssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pyopenssl
Show less packages

CVE-2013-0791

Low priority

Some fixes available 18 of 26

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey...

6 affected packages

firefox, nss, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
nss
seamonkey
thunderbird
xulrunner-1.9.2
xulrunner-2.0
Show less packages

CVE-2013-2566

Low priority

Some fixes available 8 of 17

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large...

3 affected packages

firefox, openssl, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
openssl
thunderbird
Show less packages

CVE-2010-5107

Low priority
Ignored

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot...

1 affected package

openssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh
Show less packages

CVE-2013-0288

Medium priority

Some fixes available 1 of 6

nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large...

1 affected package

nss-pam-ldapd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nss-pam-ldapd
Show less packages

CVE-2013-1620

Medium priority

Some fixes available 4 of 5

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote...

1 affected package

nss

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nss
Show less packages

CVE-2013-0169

Medium priority

Some fixes available 25 of 28

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of...

4 affected packages

openjdk-6, openjdk-7, openssl, openssl098

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjdk-6
openjdk-7
openssl
openssl098
Show less packages

CVE-2013-0166

Medium priority

Some fixes available 11 of 14

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and...

2 affected packages

openssl, openssl098

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl
openssl098
Show less packages