Search CVE reports
611 – 620 of 50657 results
[Heap OOB Read in VLAN Decapsulation memmove]
2 affected packages
lldpd, openvswitch
| Package | 16.04 LTS |
|---|---|
| lldpd | — |
| openvswitch | Needs evaluation |
Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could...
1 affected package
unbound
| Package | 16.04 LTS |
|---|---|
| unbound | Needs evaluation |
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with...
1 affected package
unbound
| Package | 16.04 LTS |
|---|---|
| unbound | Needs evaluation |
[Unknown description]
1 affected package
vim
| Package | 16.04 LTS |
|---|---|
| vim | Vulnerable |
Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Fixed |
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick...
1 affected package
unbound
| Package | 16.04 LTS |
|---|---|
| unbound | Fixed |