Search CVE reports
1 – 10 of 29316 results
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |
[Unknown description]
1 affected package
apptainer
| Package | 26.04 LTS |
|---|---|
| apptainer | Needs evaluation |
[Unknown description]
1 affected package
singularity-container
| Package | 26.04 LTS |
|---|---|
| singularity-container | Needs evaluation |
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular...
1 affected package
nsd
| Package | 26.04 LTS |
|---|---|
| nsd | Fixed |
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111...
1 affected package
nsd
| Package | 26.04 LTS |
|---|---|
| nsd | Fixed |
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the...
1 affected package
nsd
| Package | 26.04 LTS |
|---|---|
| nsd | Fixed |
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used...
1 affected package
nsd
| Package | 26.04 LTS |
|---|---|
| nsd | Fixed |
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...
1 affected package
gegl
| Package | 26.04 LTS |
|---|---|
| gegl | Not affected |
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form:...
1 affected package
rclone
| Package | 26.04 LTS |
|---|---|
| rclone | Needs evaluation |
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing...
1 affected package
mistune
| Package | 26.04 LTS |
|---|---|
| mistune | Needs evaluation |