Search CVE reports
471 – 480 of 59015 results
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...
1 affected package
c-ares
| Package | 16.04 LTS |
|---|---|
| c-ares | Needs evaluation |
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser...
1 affected package
icinga2
| Package | 16.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by...
1 affected package
icinga2
| Package | 16.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker...
1 affected package
icinga2
| Package | 16.04 LTS |
|---|---|
| icinga2 | Needs evaluation |
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation....
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the...
1 affected package
btrbk
| Package | 16.04 LTS |
|---|---|
| btrbk | Needs evaluation |
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an...
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Not affected |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec,...
1 affected package
openimageio
| Package | 16.04 LTS |
|---|---|
| openimageio | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make...
1 affected package
openimageio
| Package | 16.04 LTS |
|---|---|
| openimageio | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that...
1 affected package
openimageio
| Package | 16.04 LTS |
|---|---|
| openimageio | Needs evaluation |