Search CVE reports
2521 – 2530 of 50764 results
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or...
1 affected package
trafficserver
| Package | 16.04 LTS |
|---|---|
| trafficserver | Ignored |
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with...
1 affected package
mbedtls
| Package | 16.04 LTS |
|---|---|
| mbedtls | Ignored |
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with...
1 affected package
modsecurity-crs
| Package | 16.04 LTS |
|---|---|
| modsecurity-crs | Ignored |
A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument...
8 affected packages
darktable, dcraw, digikam, exactimage, kodi...
| Package | 16.04 LTS |
|---|---|
| darktable | Ignored |
| dcraw | Ignored |
| digikam | Ignored |
| exactimage | Ignored |
| kodi | Ignored |
| libraw | Not affected |
| rawtherapee | Ignored |
| ufraw | Ignored |
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration...
1 affected package
glances
| Package | 16.04 LTS |
|---|---|
| glances | Ignored |
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response....
1 affected package
glances
| Package | 16.04 LTS |
|---|---|
| glances | Ignored |
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Ignored |
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Ignored |
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Ignored |
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Ignored |