Search CVE reports
21 – 30 of 95 results
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift...
1 affected package
haproxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
haproxy | — | Fixed | Fixed | Not affected |
Some fixes available 11 of 94
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
24 affected packages
coin3, vnc4, vtk, xmlrpc-c, libxmltok...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
vnc4 | — | Not in release | Not in release | Needs evaluation |
vtk | — | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
firefox | Not affected | Not affected | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
cableswig | — | Not in release | Not in release | Not in release |
ayttm | — | Not in release | Not in release | Not in release |
insighttoolkit | — | Not in release | Not in release | Not in release |
smart | — | Not in release | Not in release | Not affected |
Some fixes available 13 of 118
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
24 affected packages
coin3, gdcm, vnc4, vtk, xmlrpc-c...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | — | Not in release | Not in release | Needs evaluation |
vtk | — | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
cmake | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
firefox | Not affected | Not affected | Fixed | Fixed |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
thunderbird | Ignored | Ignored | Not in release | Ignored |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ayttm | — | Not in release | Not in release | Not in release |
cableswig | — | Not in release | Not in release | Not in release |
smart | — | Not in release | Not in release | Needs evaluation |
insighttoolkit | — | Not in release | Not in release | Not in release |
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.
1 affected package
apr
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apr | — | Not affected | Not affected | Not affected |
Some fixes available 19 of 109
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
24 affected packages
vnc4, vtk, xmlrpc-c, matanza, expat...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 17 of 107
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
24 affected packages
coin3, vtk, xmlrpc-c, matanza, expat...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 19 of 109
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
24 affected packages
coin3, vtk, xmlrpc-c, matanza, expat...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 26 of 120
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
24 affected packages
libxmltok, expat, apache2, apr-util, cmake...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libxmltok | Fixed | Fixed | Fixed | Fixed |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
Some fixes available 26 of 120
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
24 affected packages
xmlrpc-c, libxmltok, vtk, smart, expat...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
libxmltok | Fixed | Fixed | Fixed | Fixed |
vtk | Not in release | Not in release | Not in release | Not in release |
smart | Not in release | Not in release | Not in release | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
firefox | Fixed | Fixed | Not in release | Ignored |
thunderbird | Ignored | Ignored | Not in release | Ignored |
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility...
1 affected package
apr-util
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apr-util | — | Fixed | Fixed | Fixed |