Search CVE reports
81 – 90 of 54248 results
In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command- line username, leading to injection.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssh | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| openssh-ssh1 | Ignored | Ignored | Ignored | Ignored | Ignored |
| openssh-gssapi | Not in release | Not in release | Not in release | — | — |
(A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF ...)
2 affected packages
hdf5, r-bioc-rhdf5lib
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| hdf5 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| r-bioc-rhdf5lib | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
(Twisted is an event-based framework for internet applications, support ...)
1 affected package
twisted
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| twisted | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ ...)
1 affected package
lz4-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| lz4-java | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |