Search CVE reports
41 – 50 of 52634 results
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available,...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a...
2 affected packages
gst-plugins-good0.10, gst-plugins-good1.0
| Package | 16.04 LTS |
|---|---|
| gst-plugins-good0.10 | — |
| gst-plugins-good1.0 | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the...
2 affected packages
erlang-cowboy, rabbitmq-server
| Package | 16.04 LTS |
|---|---|
| erlang-cowboy | — |
| rabbitmq-server | Needs evaluation |
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and...
2 affected packages
erlang-cowlib, rabbitmq-server
| Package | 16.04 LTS |
|---|---|
| erlang-cowlib | — |
| rabbitmq-server | Needs evaluation |
TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.
1 affected package
samba
| Package | 16.04 LTS |
|---|---|
| samba | Needs evaluation |
The CTDB protocol has bounds checking issues. CTDB fails to do integrity checking of received packets. This includes failure to check field lengths against packet lengths when unmarshalling packets.
1 affected package
samba
| Package | 16.04 LTS |
|---|---|
| samba | Needs evaluation |
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied...
1 affected package
samba
| Package | 16.04 LTS |
|---|---|
| samba | Needs evaluation |