Search CVE reports
3021 – 3030 of 39001 results
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
15 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 18.04 LTS |
---|---|
golang | — |
golang-1.6 | — |
golang-1.8 | Needs evaluation |
golang-1.9 | Needs evaluation |
golang-1.10 | Needs evaluation |
golang-1.13 | Needs evaluation |
golang-1.14 | — |
golang-1.16 | Needs evaluation |
golang-1.17 | — |
golang-1.18 | Needs evaluation |
golang-1.20 | — |
golang-1.21 | — |
golang-1.22 | — |
golang-1.23 | — |
golang-1.24 | — |
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
15 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 18.04 LTS |
---|---|
golang | — |
golang-1.6 | — |
golang-1.8 | Needs evaluation |
golang-1.9 | Needs evaluation |
golang-1.10 | Needs evaluation |
golang-1.13 | Needs evaluation |
golang-1.14 | — |
golang-1.16 | Needs evaluation |
golang-1.17 | — |
golang-1.18 | Needs evaluation |
golang-1.20 | — |
golang-1.21 | — |
golang-1.22 | — |
golang-1.23 | — |
golang-1.24 | — |
pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow...
1 affected package
libpgjava
Package | 18.04 LTS |
---|---|
libpgjava | Needs evaluation |
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and...
1 affected package
nomad
Package | 18.04 LTS |
---|---|
nomad | Needs evaluation |
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
1 affected package
libcryptx-perl
Package | 18.04 LTS |
---|---|
libcryptx-perl | Needs evaluation |
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 18.04 LTS |
---|---|
firefox | — |
thunderbird | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
mozjs102 | — |
mozjs115 | — |
Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 18.04 LTS |
---|---|
firefox | — |
thunderbird | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
mozjs102 | — |
mozjs115 | — |
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how...
3 affected packages
qt6-base, qtbase-opensource-src-gles, qtbase-opensource-src
Package | 18.04 LTS |
---|---|
qt6-base | — |
qtbase-opensource-src-gles | — |
qtbase-opensource-src | Vulnerable |
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh,...
1 affected package
konsole
Package | 18.04 LTS |
---|---|
konsole | Needs evaluation |
Not in release
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet9
Package | 18.04 LTS |
---|---|
dotnet6 | Not in release |
dotnet7 | Not in release |
dotnet8 | Not in release |
dotnet9 | Not in release |