Search CVE reports
741 – 750 of 54269 results
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to...
1 affected package
libthrift-java
| Package | 22.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in...
4 affected packages
php-horde-thrift, python-thrift, ruby-thrift, thrift
| Package | 22.04 LTS |
|---|---|
| php-horde-thrift | Not in release |
| python-thrift | Not in release |
| ruby-thrift | Needs evaluation |
| thrift | Needs evaluation |
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can...
1 affected package
apache-directory-api
| Package | 22.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length...
1 affected package
wss4j
| Package | 22.04 LTS |
|---|---|
| wss4j | Needs evaluation |
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This...
1 affected package
freetype
| Package | 22.04 LTS |
|---|---|
| freetype | Fixed |