Search CVE reports
14861 – 14870 of 44652 results
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own...
1 affected package
curl
Package | 16.04 LTS |
---|---|
curl | Fixed |
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows...
1 affected package
curl
Package | 16.04 LTS |
---|---|
curl | Not affected |
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before...
1 affected package
curl
Package | 16.04 LTS |
---|---|
curl | Not affected |
Mishandling of guest SSBD selection on AMD hardware The current logic to set SSBD on AMD Family 17h and Hygon Family 18h processors requires that the setting of SSBD is coordinated at a core level, as the setting is shared between...
1 affected package
xen
Package | 16.04 LTS |
---|---|
xen | Needs evaluation |
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer...
1 affected package
tiff
Package | 16.04 LTS |
---|---|
tiff | Not affected |
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible...
1 affected package
cups-filters
Package | 16.04 LTS |
---|---|
cups-filters | Fixed |
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder...
1 affected package
libreswan
Package | 16.04 LTS |
---|---|
libreswan | Ignored |
Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability...
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Not affected |
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security...
1 affected package
chromium-browser
Package | 16.04 LTS |
---|---|
chromium-browser | Ignored |
Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security...
1 affected package
chromium-browser
Package | 16.04 LTS |
---|---|
chromium-browser | Ignored |