Search CVE reports


Toggle filters

41891 – 41900 of 69503 results


CVE-2018-16947

Medium priority
Vulnerable

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results...

1 affected package

openafs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openafs Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1114

Medium priority
Needs evaluation

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

1 affected package

undertow

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-10935

Medium priority
Vulnerable

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

1 affected package

389-ds-base

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
389-ds-base Needs evaluation Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-10893

Medium priority
Vulnerable

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

1 affected package

spice-gtk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spice-gtk Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-16831

Medium priority

Some fixes available 1 of 2

Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.

1 affected package

smarty3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
smarty3 Not affected Not affected Fixed
Show less packages

CVE-2016-7074

Medium priority
Ignored

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7073

Medium priority
Ignored

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7069

Medium priority
Ignored

An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT...

1 affected package

dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7068

Low priority

Some fixes available 1 of 7

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-16807

Medium priority
Needs evaluation

In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.

1 affected package

bro

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bro Not in release Not in release Not in release Not in release Needs evaluation
Show less packages