Search CVE reports
1291 – 1300 of 50662 results
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Not affected |
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Not affected |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...
1 affected package
prometheus
| Package | 16.04 LTS |
|---|---|
| prometheus | Ignored |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...
1 affected package
prometheus
| Package | 16.04 LTS |
|---|---|
| prometheus | Ignored |
CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...
1 affected package
cimg
| Package | 16.04 LTS |
|---|---|
| cimg | Ignored |
CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...
1 affected package
cimg
| Package | 16.04 LTS |
|---|---|
| cimg | Ignored |