Search CVE reports
381 – 390 of 44355 results
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker...
1 affected package
dogtag-pki
| Package | 20.04 LTS |
|---|---|
| dogtag-pki | Needs evaluation |
A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
| Package | 20.04 LTS |
|---|---|
| gst-plugins-good0.10 | — |
| gst-plugins-good1.0 | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the...
2 affected packages
erlang-cowboy, rabbitmq-server
| Package | 20.04 LTS |
|---|---|
| erlang-cowboy | Needs evaluation |
| rabbitmq-server | Needs evaluation |
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and...
2 affected packages
erlang-cowlib, rabbitmq-server
| Package | 20.04 LTS |
|---|---|
| erlang-cowlib | Needs evaluation |
| rabbitmq-server | Needs evaluation |
TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |
The CTDB protocol has bounds checking issues. CTDB fails to do integrity checking of received packets. This includes failure to check field lengths against packet lengths when unmarshalling packets.
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied...
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |
Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover.
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a...
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the...
1 affected package
samba
| Package | 20.04 LTS |
|---|---|
| samba | Needs evaluation |