Search CVE reports
1 – 10 of 34382 results
Not in release
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
Package | 20.04 LTS |
---|---|
dotnet6 | Not in release |
dotnet7 | Not in release |
dotnet8 | Not in release |
dotnet9 | Not in release |
dotnet10 | Not in release |
Not in release
MITM (man in the middle) attacker may prevent use of TLS between client and SMTP server, forcing client to send data over unencrypted connection.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
Package | 20.04 LTS |
---|---|
dotnet6 | Not in release |
dotnet7 | Not in release |
dotnet8 | Not in release |
dotnet9 | Not in release |
dotnet10 | Not in release |
Not in release
A vulnerability exists in .NET Core where predictable paths for MSBuild's temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
Package | 20.04 LTS |
---|---|
dotnet6 | Not in release |
dotnet7 | Not in release |
dotnet8 | Not in release |
dotnet9 | Not in release |
dotnet10 | Not in release |
In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create...
146 affected packages
linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux, linux-hwe-5.11...
Package | 20.04 LTS |
---|---|
linux-hwe | Not in release |
linux-hwe-5.4 | Not in release |
linux-hwe-5.8 | Ignored |
linux | Not affected |
linux-hwe-5.11 | Ignored |
linux-hwe-5.13 | Ignored |
linux-hwe-5.15 | Not affected |
linux-hwe-5.19 | Not in release |
linux-hwe-6.2 | Not in release |
linux-hwe-6.5 | Not in release |
linux-hwe-6.8 | Not in release |
linux-hwe-6.11 | Not in release |
linux-hwe-6.14 | Not in release |
linux-hwe-edge | Not in release |
linux-lts-xenial | Not in release |
linux-kvm | Not affected |
linux-allwinner-5.19 | Not in release |
linux-aws-5.0 | Not in release |
linux-aws-5.3 | Not in release |
linux-aws | Not affected |
linux-aws-5.4 | Not in release |
linux-aws-5.8 | Ignored |
linux-aws-5.11 | Ignored |
linux-aws-5.13 | Ignored |
linux-aws-5.15 | Not affected |
linux-aws-5.19 | Not in release |
linux-aws-6.2 | Not in release |
linux-aws-6.5 | Not in release |
linux-aws-6.8 | Not in release |
linux-aws-6.14 | Not in release |
linux-aws-hwe | Not in release |
linux-azure | Not affected |
linux-azure-4.15 | Not in release |
linux-azure-5.3 | Not in release |
linux-azure-5.4 | Not in release |
linux-azure-5.8 | Ignored |
linux-azure-5.11 | Ignored |
linux-azure-5.13 | Ignored |
linux-azure-5.15 | Not affected |
linux-azure-5.19 | Not in release |
linux-azure-6.2 | Not in release |
linux-azure-6.5 | Not in release |
linux-azure-6.8 | Not in release |
linux-azure-6.11 | Not in release |
linux-azure-6.14 | Not in release |
linux-azure-fde | Ignored |
linux-azure-fde-5.15 | Not affected |
linux-azure-fde-5.19 | Not in release |
linux-azure-fde-6.2 | Not in release |
linux-azure-fde-6.14 | Not in release |
linux-azure-nvidia | Not in release |
linux-azure-nvidia-6.14 | Not in release |
linux-bluefield | Not affected |
linux-azure-edge | Not in release |
linux-fips | Not affected |
linux-aws-fips | Not affected |
linux-azure-fips | Not affected |
linux-gcp-fips | Not affected |
linux-gcp | Not affected |
linux-gcp-4.15 | Not in release |
linux-gcp-5.3 | Not in release |
linux-gcp-5.4 | Not in release |
linux-gcp-5.8 | Ignored |
linux-gcp-5.11 | Ignored |
linux-gcp-5.13 | Ignored |
linux-gcp-5.15 | Not affected |
linux-gcp-5.19 | Not in release |
linux-gcp-6.2 | Not in release |
linux-gcp-6.5 | Not in release |
linux-gcp-6.8 | Not in release |
linux-gcp-6.11 | Not in release |
linux-gcp-6.14 | Not in release |
linux-gke | Ignored |
linux-gke-4.15 | Not in release |
linux-gke-5.4 | Not in release |
linux-gke-5.15 | Ignored |
linux-gkeop | Ignored |
linux-gkeop-5.4 | Not in release |
linux-gkeop-5.15 | Ignored |
linux-ibm | Not affected |
linux-ibm-5.4 | Not in release |
linux-ibm-5.15 | Not affected |
linux-ibm-6.8 | Not in release |
linux-intel-5.13 | Ignored |
linux-intel-iotg | Not in release |
linux-intel-iotg-5.15 | Not affected |
linux-iot | Not affected |
linux-intel-iot-realtime | Not in release |
linux-lowlatency | Not in release |
linux-lowlatency-hwe-5.15 | Not affected |
linux-lowlatency-hwe-5.19 | Not in release |
linux-lowlatency-hwe-6.2 | Not in release |
linux-lowlatency-hwe-6.5 | Not in release |
linux-lowlatency-hwe-6.8 | Not in release |
linux-lowlatency-hwe-6.11 | Not in release |
linux-nvidia | Not in release |
linux-nvidia-6.2 | Not in release |
linux-nvidia-6.5 | Not in release |
linux-nvidia-6.8 | Not in release |
linux-nvidia-6.11 | Not in release |
linux-nvidia-lowlatency | Not in release |
linux-nvidia-tegra | Not in release |
linux-nvidia-tegra-5.15 | Not affected |
linux-nvidia-tegra-igx | Not in release |
linux-oracle-5.0 | Not in release |
linux-oracle-5.3 | Not in release |
linux-oracle-5.4 | Not in release |
linux-oracle-5.8 | Ignored |
linux-oracle-5.11 | Ignored |
linux-oracle-5.13 | Ignored |
linux-oracle-5.15 | Not affected |
linux-oracle-6.5 | Not in release |
linux-oracle-6.8 | Not in release |
linux-oracle-6.14 | Not in release |
linux-oem | Not in release |
linux-oem-5.6 | Ignored |
linux-oem-5.10 | Ignored |
linux-oem-5.13 | Ignored |
linux-oem-5.14 | Ignored |
linux-oem-5.17 | Not in release |
linux-oem-6.0 | Not in release |
linux-oem-6.1 | Not in release |
linux-oem-6.5 | Not in release |
linux-oem-6.8 | Not in release |
linux-oem-6.11 | Not in release |
linux-oem-6.14 | Not in release |
linux-raspi2 | Ignored |
linux-raspi-5.4 | Not in release |
linux-raspi-realtime | Not in release |
linux-realtime-6.8 | Not in release |
linux-realtime-6.14 | Not in release |
linux-riscv | Ignored |
linux-riscv-5.8 | Ignored |
linux-riscv-5.11 | Ignored |
linux-riscv-5.15 | Not affected |
linux-riscv-5.19 | Not in release |
linux-riscv-6.5 | Not in release |
linux-riscv-6.8 | Not in release |
linux-riscv-6.14 | Not in release |
linux-starfive-5.19 | Not in release |
linux-starfive-6.2 | Not in release |
linux-starfive-6.5 | Not in release |
linux-xilinx-zynqmp | Not affected |
linux-oracle | Not affected |
linux-raspi | Not affected |
linux-realtime | Not in release |
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an...
146 affected packages
linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11, linux-hwe-5.13...
Package | 20.04 LTS |
---|---|
linux-hwe | Not in release |
linux-hwe-5.4 | Not in release |
linux-hwe-5.8 | Ignored |
linux-hwe-5.11 | Ignored |
linux-hwe-5.13 | Ignored |
linux-hwe-5.15 | Ignored |
linux-hwe-5.19 | Not in release |
linux-hwe-6.2 | Not in release |
linux-hwe-6.5 | Not in release |
linux-hwe-6.8 | Not in release |
linux-hwe-6.11 | Not in release |
linux-hwe-6.14 | Not in release |
linux-hwe-edge | Not in release |
linux-lts-xenial | Not in release |
linux | Ignored |
linux-kvm | Ignored |
linux-allwinner-5.19 | Not in release |
linux-aws-5.0 | Not in release |
linux-aws-5.3 | Not in release |
linux-aws-5.4 | Not in release |
linux-aws-5.8 | Ignored |
linux-aws-5.11 | Ignored |
linux-aws-5.13 | Ignored |
linux-aws-5.15 | Ignored |
linux-aws-5.19 | Not in release |
linux-aws-6.2 | Not in release |
linux-aws-6.5 | Not in release |
linux-aws-6.8 | Not in release |
linux-aws-6.14 | Not in release |
linux-aws-hwe | Not in release |
linux-azure | Ignored |
linux-azure-4.15 | Not in release |
linux-azure-5.3 | Not in release |
linux-azure-5.4 | Not in release |
linux-azure-5.8 | Ignored |
linux-azure-5.11 | Ignored |
linux-azure-5.13 | Ignored |
linux-azure-5.15 | Ignored |
linux-azure-5.19 | Not in release |
linux-azure-6.2 | Not in release |
linux-azure-6.5 | Not in release |
linux-azure-6.8 | Not in release |
linux-azure-6.11 | Not in release |
linux-azure-6.14 | Not in release |
linux-azure-fde | Ignored |
linux-azure-fde-5.15 | Not affected |
linux-azure-fde-5.19 | Not in release |
linux-azure-fde-6.2 | Not in release |
linux-azure-fde-6.14 | Not in release |
linux-azure-nvidia | Not in release |
linux-azure-nvidia-6.14 | Not in release |
linux-bluefield | Ignored |
linux-azure-edge | Not in release |
linux-fips | Vulnerable |
linux-aws-fips | Vulnerable |
linux-azure-fips | Vulnerable |
linux-gcp-fips | Vulnerable |
linux-gcp | Ignored |
linux-gcp-4.15 | Not in release |
linux-gcp-5.3 | Not in release |
linux-gcp-5.4 | Not in release |
linux-gcp-5.8 | Ignored |
linux-gcp-5.11 | Ignored |
linux-gcp-5.13 | Ignored |
linux-gcp-5.15 | Ignored |
linux-gcp-5.19 | Not in release |
linux-gcp-6.2 | Not in release |
linux-gcp-6.5 | Not in release |
linux-gcp-6.8 | Not in release |
linux-gcp-6.11 | Not in release |
linux-gcp-6.14 | Not in release |
linux-gke | Ignored |
linux-gke-4.15 | Not in release |
linux-gke-5.4 | Not in release |
linux-gke-5.15 | Ignored |
linux-gkeop | Ignored |
linux-gkeop-5.4 | Not in release |
linux-gkeop-5.15 | Ignored |
linux-ibm | Ignored |
linux-ibm-5.4 | Not in release |
linux-ibm-5.15 | Ignored |
linux-ibm-6.8 | Not in release |
linux-intel-5.13 | Ignored |
linux-intel-iotg | Not in release |
linux-intel-iotg-5.15 | Ignored |
linux-iot | Ignored |
linux-intel-iot-realtime | Not in release |
linux-lowlatency | Not in release |
linux-lowlatency-hwe-5.15 | Ignored |
linux-lowlatency-hwe-5.19 | Not in release |
linux-lowlatency-hwe-6.2 | Not in release |
linux-lowlatency-hwe-6.5 | Not in release |
linux-lowlatency-hwe-6.8 | Not in release |
linux-lowlatency-hwe-6.11 | Not in release |
linux-nvidia | Not in release |
linux-nvidia-6.2 | Not in release |
linux-nvidia-6.5 | Not in release |
linux-nvidia-6.8 | Not in release |
linux-nvidia-6.11 | Not in release |
linux-nvidia-lowlatency | Not in release |
linux-nvidia-tegra | Not in release |
linux-nvidia-tegra-5.15 | Ignored |
linux-nvidia-tegra-igx | Not in release |
linux-oracle-5.0 | Not in release |
linux-oracle-5.3 | Not in release |
linux-oracle-5.4 | Not in release |
linux-oracle-5.8 | Ignored |
linux-oracle-5.11 | Ignored |
linux-oracle-5.13 | Ignored |
linux-oracle-5.15 | Ignored |
linux-oracle-6.5 | Not in release |
linux-oracle-6.8 | Not in release |
linux-oracle-6.14 | Not in release |
linux-oem | Not in release |
linux-oem-5.6 | Ignored |
linux-oem-5.10 | Ignored |
linux-oem-5.13 | Ignored |
linux-oem-5.14 | Ignored |
linux-oem-5.17 | Not in release |
linux-oem-6.0 | Not in release |
linux-oem-6.1 | Not in release |
linux-oem-6.5 | Not in release |
linux-oem-6.8 | Not in release |
linux-oem-6.11 | Not in release |
linux-oem-6.14 | Not in release |
linux-raspi2 | Ignored |
linux-raspi-5.4 | Not in release |
linux-raspi-realtime | Not in release |
linux-realtime-6.8 | Not in release |
linux-realtime-6.14 | Not in release |
linux-riscv | Ignored |
linux-riscv-5.8 | Ignored |
linux-riscv-5.11 | Ignored |
linux-riscv-5.15 | Ignored |
linux-riscv-5.19 | Not in release |
linux-riscv-6.5 | Not in release |
linux-riscv-6.8 | Not in release |
linux-riscv-6.14 | Not in release |
linux-starfive-5.19 | Not in release |
linux-starfive-6.2 | Not in release |
linux-starfive-6.5 | Not in release |
linux-xilinx-zynqmp | Ignored |
linux-aws | Ignored |
linux-oracle | Ignored |
linux-raspi | Ignored |
linux-realtime | Not in release |
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the...
1 affected package
ruby-sinatra
Package | 20.04 LTS |
---|---|
ruby-sinatra | Needs evaluation |
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`,...
1 affected package
ruby-rack
Package | 20.04 LTS |
---|---|
ruby-rack | Needs evaluation |
python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of...
1 affected package
python-ldap
Package | 20.04 LTS |
---|---|
python-ldap | Needs evaluation |
python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to skip escaping of special characters when...
1 affected package
python-ldap
Package | 20.04 LTS |
---|---|
python-ldap | Needs evaluation |
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers...
1 affected package
ruby-rack
Package | 20.04 LTS |
---|---|
ruby-rack | Needs evaluation |