Search CVE reports


Toggle filters

291 – 300 of 498 results


CVE-2018-1283

Low priority
Fixed

In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — Fixed
Show less packages

CVE-2017-15715

Low priority
Fixed

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — Fixed
Show less packages

CVE-2017-15710

Low priority
Fixed

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — Fixed
Show less packages

CVE-2011-4973

Medium priority
Vulnerable

Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.

1 affected package

libapache2-mod-nss

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-nss Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2018-6508

Medium priority
Needs evaluation

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected...

3 affected packages

puppet-module-puppetlabs-apt, puppet-module-puppetlabs-apache, puppet-module-puppetlabs-mysql

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet-module-puppetlabs-apt Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
puppet-module-puppetlabs-apache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
puppet-module-puppetlabs-mysql Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-12626

Medium priority
Vulnerable

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing...

1 affected package

libapache-poi-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-poi-java Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-9798

Medium priority
Fixed

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages

CVE-2017-2299

Medium priority
Vulnerable

Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be...

1 affected package

puppet-module-puppetlabs-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet-module-puppetlabs-apache Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-3250

Medium priority
Fixed

Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

1 affected package

apache-directory-api

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache-directory-api — — — Not affected Not affected
Show less packages

CVE-2015-3277

Medium priority
Vulnerable

The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of multi-keyword cipherstring.

1 affected package

libapache2-mod-nss

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-nss Not in release Not in release Not in release Not in release Vulnerable
Show less packages