Search CVE reports
401 – 410 of 60208 results
In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
security update
6 affected packages
chromium-browser, webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 16.04 LTS |
|---|---|
| chromium-browser | — |
| webkitgtk | Ignored |
| webkit2gtk | Ignored |
| qtwebkit-source | Ignored |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | — |
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the...
1 affected package
libyaml-perl
| Package | 16.04 LTS |
|---|---|
| libyaml-perl | Needs evaluation |
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls...
1 affected package
libyaml-perl
| Package | 16.04 LTS |
|---|---|
| libyaml-perl | Needs evaluation |
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any...
1 affected package
gist
| Package | 16.04 LTS |
|---|---|
| gist | Needs evaluation |
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the...
1 affected package
imagemagick
| Package | 16.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The...
1 affected package
dogtag-pki
| Package | 16.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which...
1 affected package
trafficserver
| Package | 16.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender...
1 affected package
logback
| Package | 16.04 LTS |
|---|---|
| logback | Needs evaluation |