Search CVE reports
2431 – 2440 of 38328 results
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the...
1 affected package
curl
Package | 18.04 LTS |
---|---|
curl | Not affected |
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
1 affected package
curl
Package | 18.04 LTS |
---|---|
curl | Not affected |
In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
1 affected package
isc-kea
Package | 18.04 LTS |
---|---|
isc-kea | Not affected |
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the...
1 affected package
isc-kea
Package | 18.04 LTS |
---|---|
isc-kea | Not affected |
Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in...
1 affected package
isc-kea
Package | 18.04 LTS |
---|---|
isc-kea | Not affected |
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional...
1 affected package
coreutils
Package | 18.04 LTS |
---|---|
coreutils | Needs evaluation |
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate()...
1 affected package
icinga2
Package | 18.04 LTS |
---|---|
icinga2 | Needs evaluation |
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a...
1 affected package
nvidia-cuda-toolkit
Package | 18.04 LTS |
---|---|
nvidia-cuda-toolkit | Needs evaluation |
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption....
1 affected package
binutils
Package | 18.04 LTS |
---|---|
binutils | Vulnerable |
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to...
1 affected package
gimp
Package | 18.04 LTS |
---|---|
gimp | Needs evaluation |