Search CVE reports
511 – 520 of 59015 results
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over...
2 affected packages
qemu, qemu-hwe
| Package | 16.04 LTS |
|---|---|
| qemu | Needs evaluation |
| qemu-hwe | — |
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 16.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | — |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 16.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | — |
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9...
1 affected package
wordpress
| Package | 16.04 LTS |
|---|---|
| wordpress | Needs evaluation |