Search CVE reports
881 – 890 of 49990 results
cross-proxy Digest auth state leak
1 affected package
curl
| Package | 16.04 LTS |
|---|---|
| curl | Needs evaluation |
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods...
1 affected package
libtext-csv-xs-perl
| Package | 16.04 LTS |
|---|---|
| libtext-csv-xs-perl | Needs evaluation |
OCSP stapling bypass with Apple SecTrust
1 affected package
curl
| Package | 16.04 LTS |
|---|---|
| curl | Not affected |
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the...
1 affected package
libpgjava
| Package | 16.04 LTS |
|---|---|
| libpgjava | Needs evaluation |
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP...
1 affected package
starman
| Package | 16.04 LTS |
|---|---|
| starman | Needs evaluation |
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or...
2 affected packages
glibc, eglibc
| Package | 16.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
1 affected package
nano
| Package | 16.04 LTS |
|---|---|
| nano | Not affected |
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
2 affected packages
glibc, eglibc
| Package | 16.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell....
2 affected packages
kcoreaddons, kf6-kcoreaddons
| Package | 16.04 LTS |
|---|---|
| kcoreaddons | Needs evaluation |
| kf6-kcoreaddons | — |
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol...
1 affected package
dolphin
| Package | 16.04 LTS |
|---|---|
| dolphin | Needs evaluation |