Search CVE reports


Toggle filters

461 – 470 of 498 results


CVE-2006-2314

Medium priority

Some fixes available 21 of 24

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte...

14 affected packages

amarok, dovecot, exim4, libapache2-mod-auth-pgsql, php5...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
amarok — — — — —
dovecot — — — — —
exim4 — — — — —
libapache2-mod-auth-pgsql — — — — —
php5 — — — — —
postfix — — — — —
postgresql — — — — —
postgresql-7.4 — — — — —
postgresql-8.1 — — — — —
postgresql-8.2 — — — — —
psycopg — — — — —
psycopg2 — — — — —
pygresql — — — — —
python-pgsql — — — — —
Show all 14 packages Show less packages

CVE-2006-1095

Medium priority
Not affected

Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.

1 affected package

libapache2-mod-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-python — — — — —
Show less packages

CVE-2006-0150

Medium priority

Not in release

Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.

1 affected package

libapache-auth-ldap

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-auth-ldap — — — — —
Show less packages

CVE-2005-3656

Medium priority
Fixed

Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as...

1 affected package

libapache2-mod-auth-pgsql

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-pgsql — — — — —
Show less packages

CVE-2005-3357

Medium priority
Fixed

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages

CVE-2005-3352

Medium priority
Fixed

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using...

2 affected packages

apache, apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache — — — — —
apache2 — — — — —
Show less packages

CVE-2005-2970

Medium priority
Not affected

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages

CVE-2005-2660

Medium priority
Fixed

apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.

1 affected package

apachetop

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apachetop — — — — —
Show less packages

CVE-2005-2700

Medium priority
Fixed

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote...

2 affected packages

apache2, libapache-mod-ssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
libapache-mod-ssl — — — — —
Show less packages

CVE-2005-2728

Medium priority
Fixed

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages