Search CVE reports
1 – 10 of 196 results
A bug in Apache HTTP Server 2.4.64 results in all “RewriteCond expr ...” tests evaluating as “true”. Users are recommended to upgrade to version 2.4.65, which fixes the issue.
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using...
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Needs evaluation |
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a...
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for...
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Needs evaluation |
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
apr-util | Not affected |
cmake | — |
ghostscript | — |
texlive-bin | — |
xmlrpc-c | Needs evaluation |
vnc4 | Needs evaluation |
wbxml2 | — |
swish-e | — |
insighttoolkit4 | — |
cadaver | — |
gdcm | Not affected |
ayttm | — |
cableswig | — |
coin3 | Needs evaluation |
matanza | — |
tdom | — |
vtk | Needs evaluation |
smart | — |
firefox | — |
thunderbird | — |
libxmltok | — |
expat | Ignored |
Some fixes available 1 of 5
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
apr-util | Not affected |
cmake | — |
ghostscript | — |
texlive-bin | — |
xmlrpc-c | Needs evaluation |
vnc4 | Needs evaluation |
wbxml2 | — |
swish-e | — |
insighttoolkit4 | — |
expat | Fixed |
cadaver | — |
gdcm | Not affected |
ayttm | — |
cableswig | — |
coin3 | Needs evaluation |
matanza | — |
tdom | — |
vtk | Needs evaluation |
smart | — |
firefox | — |
thunderbird | — |
libxmltok | — |
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where...
1 affected package
apache2
Package | 14.04 LTS |
---|---|
apache2 | Needs evaluation |
Some fixes available 1 of 5
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
tdom, apache2, apr-util, cmake, ghostscript...
Package | 14.04 LTS |
---|---|
tdom | — |
apache2 | Not affected |
apr-util | Not affected |
cmake | — |
ghostscript | — |
texlive-bin | — |
xmlrpc-c | Needs evaluation |
vnc4 | Needs evaluation |
wbxml2 | — |
swish-e | — |
insighttoolkit4 | — |
cadaver | — |
gdcm | Not affected |
ayttm | — |
cableswig | — |
coin3 | Needs evaluation |
matanza | — |
vtk | Needs evaluation |
smart | — |
firefox | — |
thunderbird | — |
libxmltok | — |
expat | Fixed |
Some fixes available 1 of 5
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 14.04 LTS |
---|---|
apache2 | Not affected |
apr-util | Not affected |
cmake | — |
ghostscript | — |
texlive-bin | — |
xmlrpc-c | Needs evaluation |
vnc4 | Needs evaluation |
wbxml2 | — |
swish-e | — |
insighttoolkit4 | — |
cadaver | — |
gdcm | Not affected |
ayttm | — |
cableswig | — |
coin3 | Needs evaluation |
matanza | — |
tdom | — |
vtk | Needs evaluation |
smart | — |
firefox | — |
thunderbird | — |
libxmltok | — |
expat | Fixed |