Search CVE reports


Toggle filters

41431 – 41440 of 68840 results


CVE-2018-6558

Medium priority

Some fixes available 1 of 2

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through...

1 affected package

fscrypt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fscrypt Fixed
Show less packages

CVE-2018-15822

Low priority
Fixed

The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.

1 affected package

ffmpeg

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Not affected Fixed
Show less packages

CVE-2017-2635

Low priority
Not affected

A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2016-9605

Medium priority
Ignored

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL...

2 affected packages

cobbler, maas-provision

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
maas-provision Not in release Not in release Not in release
Show less packages

CVE-2018-11776

Medium priority

Not in release

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with...

1 affected package

libstruts1.2-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstruts1.2-java Not in release
Show less packages

CVE-2018-10846

Medium priority

Some fixes available 2 of 3

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13...

2 affected packages

gnutls26, gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release Not in release Not in release Not in release Not in release
gnutls28 Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10845

Medium priority

Some fixes available 2 of 3

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical...

2 affected packages

gnutls26, gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release Not in release Not in release Not in release Not in release
gnutls28 Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10844

Medium priority

Some fixes available 2 of 3

It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical...

2 affected packages

gnutls28, gnutls26

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Not affected Not affected Not affected Not affected Fixed
gnutls26 Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-15672

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11207. Reason: This candidate is a reservation duplicate of CVE-2018-11207. Notes: All CVE users should reference CVE-2018-11207 instead of this candidate. ...

1 affected package

hdf5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected
Show less packages

CVE-2018-15671

Negligible priority
Ignored

An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.

1 affected package

hdf5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Ignored Ignored Ignored Ignored
Show less packages