Search CVE reports
11 – 20 of 40333 results
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages....
1 affected package
wss4j
| Package | 26.04 LTS |
|---|---|
| wss4j | Needs evaluation |
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd...
1 affected package
apache2
| Package | 26.04 LTS |
|---|---|
| apache2 | Needs evaluation |
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string...
1 affected package
geopy
| Package | 26.04 LTS |
|---|---|
| geopy | Needs evaluation |
[GHSA-jx3r-phvx-2jmj: XML request body processor dereferences an uninitialized parser context pointer]
1 affected package
modsecurity
| Package | 26.04 LTS |
|---|---|
| modsecurity | Needs evaluation |
[GHSA-vmg8-j66p-vgvw: Response body inspection bypass via non-canonical Content-Type casing]
1 affected package
modsecurity
| Package | 26.04 LTS |
|---|---|
| modsecurity | Needs evaluation |
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent...
1 affected package
apache2
| Package | 26.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via...
1 affected package
apache2
| Package | 26.04 LTS |
|---|---|
| apache2 | Needs evaluation |
The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this...
1 affected package
jackson-dataformat-smile
| Package | 26.04 LTS |
|---|---|
| jackson-dataformat-smile | Needs evaluation |