Search CVE reports
151 – 160 of 44512 results
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...
1 affected package
dracut
| Package | 20.04 LTS |
|---|---|
| dracut | Needs evaluation |
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...
1 affected package
bouncycastle
| Package | 20.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
local privilege escalation via missing home-record signature verification on the authenticate path
1 affected package
systemd
| Package | 20.04 LTS |
|---|---|
| systemd | Not affected |
unprivileged users can terminate arbitrary processes
1 affected package
systemd
| Package | 20.04 LTS |
|---|---|
| systemd | Not affected |
unprivileged users can terminate arbitrary processes
1 affected package
systemd
| Package | 20.04 LTS |
|---|---|
| systemd | Not affected |
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...
1 affected package
python-h2
| Package | 20.04 LTS |
|---|---|
| python-h2 | Needs evaluation |
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end...
1 affected package
node-re2
| Package | 20.04 LTS |
|---|---|
| node-re2 | Needs evaluation |
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior...
1 affected package
jsoup
| Package | 20.04 LTS |
|---|---|
| jsoup | Needs evaluation |