Search CVE reports
471 – 480 of 46621 results
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
(jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
1 affected package
jsoup
| Package | 20.04 LTS |
|---|---|
| jsoup | Needs evaluation |
(A flaw was found in FreeIPA. A remote, unauthenticated attacker can ex ...)
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
(A flaw was found in FreeIPA. A remote, unauthenticated attacker can ex ...)
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
(A flaw was found in FreeIPA. A low-privilege authenticated user can ex ...)
1 affected package
freeipa
| Package | 20.04 LTS |
|---|---|
| freeipa | Needs evaluation |
(msgpack_unpacker_expand_buffer in src/unpack.c, reached through the pu ...)
1 affected package
msgpack-c
| Package | 20.04 LTS |
|---|---|
| msgpack-c | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables...
1 affected package
coturn
| Package | 20.04 LTS |
|---|---|
| coturn | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header...
1 affected package
coturn
| Package | 20.04 LTS |
|---|---|
| coturn | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string()...
1 affected package
coturn
| Package | 20.04 LTS |
|---|---|
| coturn | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t...
1 affected package
coturn
| Package | 20.04 LTS |
|---|---|
| coturn | Needs evaluation |