Search CVE reports
61 – 70 of 41340 results
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV()...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
1 affected package
redmine
| Package | 20.04 LTS |
|---|---|
| redmine | Needs evaluation |
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
1 affected package
libcrypt-pbkdf2-perl
| Package | 20.04 LTS |
|---|---|
| libcrypt-pbkdf2-perl | Needs evaluation |
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit...
1 affected package
qemu
| Package | 20.04 LTS |
|---|---|
| qemu | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for...
1 affected package
mongodb
| Package | 20.04 LTS |
|---|---|
| mongodb | Needs evaluation |