Search CVE reports
391 – 400 of 60208 results
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the...
3 affected packages
php-horde-thrift, python-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| python-thrift | Needs evaluation |
| thrift | — |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version...
3 affected packages
libthrift-java, python-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
| python-thrift | Needs evaluation |
| thrift | — |
[virtio-gpu: disable blob scanouts on mapping cleanup]
2 affected packages
qemu, qemu-hwe
| Package | 16.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | — |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
1 affected package
libthrift-java
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
1 affected package
libthrift-java
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends...
1 affected package
libnet-whois-raw-perl
| Package | 16.04 LTS |
|---|---|
| libnet-whois-raw-perl | Needs evaluation |
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |