Search CVE reports
181 – 190 of 50365 results
[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]
5 affected packages
libpng, libpng1.6, firefox, thunderbird, chromium-browser
| Package | 20.04 LTS |
|---|---|
| libpng | — |
| libpng1.6 | Needs evaluation |
| firefox | — |
| thunderbird | — |
| chromium-browser | — |
Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | — |
Some fixes available 1 of 2
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | — |
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...
1 affected package
node-pbkdf2
| Package | 20.04 LTS |
|---|---|
| node-pbkdf2 | Needs evaluation |
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler....
1 affected package
opendmarc
| Package | 20.04 LTS |
|---|---|
| opendmarc | Needs evaluation |
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by...
1 affected package
opendmarc
| Package | 20.04 LTS |
|---|---|
| opendmarc | Needs evaluation |
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the...
1 affected package
opendmarc
| Package | 20.04 LTS |
|---|---|
| opendmarc | Needs evaluation |
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation...
1 affected package
opendmarc
| Package | 20.04 LTS |
|---|---|
| opendmarc | Needs evaluation |
A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use...
1 affected package
opendkim
| Package | 20.04 LTS |
|---|---|
| opendkim | Needs evaluation |
[lxc-copy host-context hostname update follows symlink]
1 affected package
lxc
| Package | 20.04 LTS |
|---|---|
| lxc | Needs evaluation |