Search CVE reports


Toggle filters

41281 – 41290 of 69301 results


CVE-2018-16844

Medium priority
Fixed

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the...

1 affected package

nginx

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nginx Fixed
Show less packages

CVE-2018-16843

Medium priority
Fixed

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)...

1 affected package

nginx

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nginx Fixed
Show less packages

CVE-2018-18956

Medium priority
Needs evaluation

The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in...

1 affected package

suricata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
suricata Not affected Not affected Not affected Not in release Needs evaluation
Show less packages

CVE-2018-18820

Medium priority

Some fixes available 2 of 3

A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header,...

1 affected package

icecast2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icecast2 Not affected Fixed
Show less packages

CVE-2018-18928

Medium priority
Not affected

International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.

2 affected packages

chromium-browser, icu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected
icu Not affected
Show less packages

CVE-2018-18926

Medium priority
Needs evaluation

Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.

1 affected package

golang-code.gitea-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-code.gitea-git Not in release Not in release Needs evaluation Ignored Ignored
Show less packages

CVE-2018-18915

Low priority
Not affected

There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.

1 affected package

exiv2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Not affected
Show less packages

CVE-2018-16849

Low priority

Some fixes available 2 of 11

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since...

1 affected package

mistral

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mistral Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-18897

Negligible priority
Fixed

An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-18849

Low priority
Fixed

In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed
qemu-kvm Not in release Not in release
Show less packages