Search CVE reports
721 – 730 of 56918 results
[Out-of-bounds stack array access in tdelete]
2 affected packages
glibc, eglibc
| Package | 16.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | — |
Buffer overflow in strfmon right-justification padding
2 affected packages
glibc, eglibc
| Package | 16.04 LTS |
|---|---|
| glibc | Not affected |
| eglibc | — |
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log,...
2 affected packages
ansible, ansible-core
| Package | 16.04 LTS |
|---|---|
| ansible | Needs evaluation |
| ansible-core | — |
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API...
1 affected package
netty
| Package | 16.04 LTS |
|---|---|
| netty | Needs evaluation |
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB,...
1 affected package
dia
| Package | 16.04 LTS |
|---|---|
| dia | Needs evaluation |
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
1 affected package
stomper
| Package | 16.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously...
1 affected package
stomper
| Package | 16.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its...
1 affected package
stomper
| Package | 16.04 LTS |
|---|---|
| stomper | Needs evaluation |
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of...
1 affected package
stomper
| Package | 16.04 LTS |
|---|---|
| stomper | Needs evaluation |
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in...
1 affected package
stomper
| Package | 16.04 LTS |
|---|---|
| stomper | Needs evaluation |