Search CVE reports
221 – 230 of 41463 results
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server...
1 affected package
php-guzzlehttp-psr7
| Package | 20.04 LTS |
|---|---|
| php-guzzlehttp-psr7 | Needs evaluation |
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check....
1 affected package
krb5
| Package | 20.04 LTS |
|---|---|
| krb5 | Needs evaluation |
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of...
1 affected package
spring
| Package | 20.04 LTS |
|---|---|
| spring | Needs evaluation |
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore...
1 affected package
its
| Package | 20.04 LTS |
|---|---|
| its | Needs evaluation |
[Root code execution via DHCP options command injection]
1 affected package
dracut
| Package | 20.04 LTS |
|---|---|
| dracut | Needs evaluation |
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
1 affected package
libnfs
| Package | 20.04 LTS |
|---|---|
| libnfs | Needs evaluation |
[Unknown description]
1 affected package
jq
| Package | 20.04 LTS |
|---|---|
| jq | Needs evaluation |
(Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface ...)
1 affected package
erlang
| Package | 20.04 LTS |
|---|---|
| erlang | Needs evaluation |
(Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv ...)
1 affected package
erlang
| Package | 20.04 LTS |
|---|---|
| erlang | Needs evaluation |
(Reliance on IP Address for Authentication vulnerability in Erlang/OTP ...)
1 affected package
erlang
| Package | 20.04 LTS |
|---|---|
| erlang | Needs evaluation |