Search CVE reports


Toggle filters

13771 – 13780 of 44107 results

Status is adjusted based on your filters.


CVE-2022-40896

Medium priority
Not affected

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

1 affected package

pygments

Package 16.04 LTS
pygments Not affected
Show less packages

CVE-2023-38408

Medium priority
Fixed

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not...

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Fixed
openssh-ssh1 Not in release
Show less packages

CVE-2023-3750

Medium priority
Not affected

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This...

1 affected package

libvirt

Package 16.04 LTS
libvirt Not affected
Show less packages

CVE-2023-3748

Medium priority
Ignored

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval...

1 affected package

frr

Package 16.04 LTS
frr Ignored
Show less packages

CVE-2023-34968

Medium priority
Needs evaluation

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious...

1 affected package

samba

Package 16.04 LTS
samba Needs evaluation
Show less packages

CVE-2023-34967

Medium priority
Not affected

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and...

1 affected package

samba

Package 16.04 LTS
samba Not affected
Show less packages

CVE-2023-34966

Medium priority
Fixed

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the...

1 affected package

samba

Package 16.04 LTS
samba Fixed
Show less packages

CVE-2023-3446

Low priority

Some fixes available 1 of 2

Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may...

4 affected packages

openssl1.0, nodejs, edk2, openssl

Package 16.04 LTS
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
openssl Fixed
Show less packages

CVE-2023-3347

Medium priority
Not affected

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing...

1 affected package

samba

Package 16.04 LTS
samba Not affected
Show less packages

CVE-2023-32001

Medium priority
Not affected

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

1 affected package

curl

Package 16.04 LTS
curl Not affected
Show less packages