Search CVE reports
171 – 180 of 48643 results
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through...
6 affected packages
tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11
| Package | 16.04 LTS |
|---|---|
| tomcat6 | Needs evaluation |
| tomcat7 | Needs evaluation |
| tomcat8 | Needs evaluation |
| tomcat9 | — |
| tomcat10 | — |
| tomcat11 | — |
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can...
1 affected package
gnutls28
| Package | 16.04 LTS |
|---|---|
| gnutls28 | Not affected |
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to...
1 affected package
activemq
| Package | 16.04 LTS |
|---|---|
| activemq | Needs evaluation |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...
1 affected package
osslsigncode
| Package | 16.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...
1 affected package
osslsigncode
| Package | 16.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.
1 affected package
mapserver
| Package | 16.04 LTS |
|---|---|
| mapserver | Needs evaluation |
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect...
1 affected package
libcap2
| Package | 16.04 LTS |
|---|---|
| libcap2 | Needs evaluation |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7...
1 affected package
osslsigncode
| Package | 16.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used for `PALETTE COLOR` images does not validate pixel indices against the lookup...
1 affected package
orthanc
| Package | 16.04 LTS |
|---|---|
| orthanc | Needs evaluation |
A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen...
1 affected package
orthanc
| Package | 16.04 LTS |
|---|---|
| orthanc | Needs evaluation |