Search CVE reports


Toggle filters

161 – 170 of 489 results


CVE-2015-2929

Medium priority

Some fixes available 2 of 4

The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2015-2928

Medium priority

Some fixes available 2 of 4

The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2015-2689

Low priority

Some fixes available 2 of 4

Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2015-2688

Low priority

Some fixes available 2 of 4

buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2014-9720

Low priority
Ignored

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Not affected
Show less packages

CVE-2020-7040

Medium priority

Some fixes available 3 of 5

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock...

1 affected package

storebackup

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
storebackup Fixed Fixed
Show less packages

CVE-2016-1000022

Medium priority

Some fixes available 4 of 9

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10539. Reason: This candidate is a duplicate of CVE-2016-10539. Notes: All CVE users should reference CVE-2016-10539 instead of this candidate. All references...

1 affected package

node-negotiator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-negotiator Fixed
Show less packages

CVE-2010-4654

Medium priority
Needs evaluation

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

5 affected packages

koffice, ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
koffice Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2010-4653

Low priority
Ignored

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

5 affected packages

ipe, koffice, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Not affected Not affected
koffice Not in release Not in release
libextractor Not affected Not affected
poppler Not affected Not affected
xpdf Not in release Not affected
Show less packages

CVE-2019-10219

Medium priority
Needs evaluation

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in...

1 affected package

libhibernate-validator-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages