Search CVE reports
71 – 80 of 53631 results
[virtio-gpu: disable blob scanouts on mapping cleanup]
2 affected packages
qemu, qemu-hwe
| Package | 22.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | Not in release |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
1 affected package
thrift
| Package | 22.04 LTS |
|---|---|
| thrift | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
1 affected package
libthrift-java
| Package | 22.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
1 affected package
libthrift-java
| Package | 22.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Not in release
(Insufficient Verification of Data Authenticity vulnerability in hexpm ...)
1 affected package
erlang-hex
| Package | 22.04 LTS |
|---|---|
| erlang-hex | Not in release |
(Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command ...)
1 affected package
libnet-whois-raw-perl
| Package | 22.04 LTS |
|---|---|
| libnet-whois-raw-perl | Needs evaluation |
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its...
1 affected package
bouncycastle
| Package | 22.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose...
1 affected package
bouncycastle
| Package | 22.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an...
1 affected package
bouncycastle
| Package | 22.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate...
1 affected package
bouncycastle
| Package | 22.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |