Search CVE reports


Toggle filters

91 – 100 of 366 results


CVE-2022-23181

Low priority

Some fixes available 4 of 8

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform...

2 affected packages

tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8 Fixed
tomcat9 Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-19858

Medium priority

Some fixes available 1 of 14

Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.

3 affected packages

digikam, kodi, xbmc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
digikam Not affected Not affected Fixed Not affected
kodi Needs evaluation Needs evaluation Ignored Ignored
xbmc
Show less packages

CVE-2021-42340

Medium priority
Ignored

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was...

2 affected packages

tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8 Not affected
tomcat9 Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-41079

Medium priority

Some fixes available 3 of 8

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-36370

Medium priority

Some fixes available 5 of 7

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to...

1 affected package

mc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mc Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-33037

Medium priority

Some fixes available 2 of 16

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Vulnerable
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat9 Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-30640

Medium priority

Some fixes available 2 of 16

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Vulnerable
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat9 Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-30639

Medium priority
Ignored

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Not affected
tomcat9 Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-24870

Medium priority
Needs evaluation

Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.

8 affected packages

libraw, ufraw, xbmc, darktable, dcraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2021-25329

Low priority

Some fixes available 5 of 16

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Fixed
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat9 Not affected Not affected Fixed Fixed
Show less packages