Search CVE reports
661 – 670 of 39983 results
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to...
1 affected package
apache2
| Package | 20.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write...
1 affected package
apache2
| Package | 20.04 LTS |
|---|---|
| apache2 | Needs evaluation |
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which...
1 affected package
apache2
| Package | 20.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
1 affected package
apache2
| Package | 20.04 LTS |
|---|---|
| apache2 | Not affected |
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so...
1 affected package
node-ajv
| Package | 20.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...
1 affected package
prometheus
| Package | 20.04 LTS |
|---|---|
| prometheus | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...
1 affected package
prometheus
| Package | 20.04 LTS |
|---|---|
| prometheus | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...
1 affected package
cimg
| Package | 20.04 LTS |
|---|---|
| cimg | Needs evaluation |
CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...
1 affected package
cimg
| Package | 20.04 LTS |
|---|---|
| cimg | Needs evaluation |
Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...
1 affected package
beets
| Package | 20.04 LTS |
|---|---|
| beets | Needs evaluation |