Search CVE reports
231 – 240 of 45011 results
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads...
1 affected package
horizon
| Package | 20.04 LTS |
|---|---|
| horizon | Needs evaluation |
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...
1 affected package
mongo-java-driver
| Package | 20.04 LTS |
|---|---|
| mongo-java-driver | Needs evaluation |
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...
1 affected package
389-ds-base
| Package | 20.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
(A flaw was found in dhcp-server. A remote attacker with network access ...)
1 affected package
isc-dhcp
| Package | 20.04 LTS |
|---|---|
| isc-dhcp | Needs evaluation |
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service...
1 affected package
undertow
| Package | 20.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments...
1 affected package
undertow
| Package | 20.04 LTS |
|---|---|
| undertow | Needs evaluation |