Search CVE reports
191 – 200 of 59858 results
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then...
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 16.04 LTS |
|---|---|
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | Needs evaluation |
| python3.6 | — |
| python3.7 | — |
| python3.8 | — |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and...
11 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7...
| Package | 16.04 LTS |
|---|---|
| python2.7 | Needs evaluation |
| python3.4 | — |
| python3.5 | Needs evaluation |
| python3.6 | — |
| python3.7 | — |
| python3.8 | — |
| python3.9 | — |
| python3.10 | — |
| python3.11 | — |
| python3.12 | — |
| python3.14 | — |
[GHSA-wj29-mxmc-q98c: Heap OOB read/write in MS-MPPE key re-encryption]
1 affected package
radsecproxy
| Package | 16.04 LTS |
|---|---|
| radsecproxy | Needs evaluation |
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is...
1 affected package
tnef
| Package | 16.04 LTS |
|---|---|
| tnef | Needs evaluation |
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper...
1 affected package
tnef
| Package | 16.04 LTS |
|---|---|
| tnef | Needs evaluation |
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input...
1 affected package
tnef
| Package | 16.04 LTS |
|---|---|
| tnef | Needs evaluation |