Search CVE reports
19251 – 19260 of 45622 results
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause...
1 affected package
net-snmp
| Package | 16.04 LTS |
|---|---|
| net-snmp | Fixed |
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A...
1 affected package
net-snmp
| Package | 16.04 LTS |
|---|---|
| net-snmp | Fixed |
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in...
1 affected package
net-snmp
| Package | 16.04 LTS |
|---|---|
| net-snmp | Fixed |
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory...
1 affected package
net-snmp
| Package | 16.04 LTS |
|---|---|
| net-snmp | Fixed |
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
3 affected packages
jetty, jetty8, jetty9
| Package | 16.04 LTS |
|---|---|
| jetty | Needs evaluation |
| jetty8 | Needs evaluation |
| jetty9 | Not affected |
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a...
3 affected packages
jetty, jetty8, jetty9
| Package | 16.04 LTS |
|---|---|
| jetty | Needs evaluation |
| jetty8 | Needs evaluation |
| jetty9 | Needs evaluation |
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a...
3 affected packages
jetty, jetty8, jetty9
| Package | 16.04 LTS |
|---|---|
| jetty | Needs evaluation |
| jetty8 | Needs evaluation |
| jetty9 | Needs evaluation |
Not in release
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side...
1 affected package
jenkins
| Package | 16.04 LTS |
|---|---|
| jenkins | Not in release |
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's...
1 affected package
icedtea-web
| Package | 16.04 LTS |
|---|---|
| icedtea-web | Needs evaluation |
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can...
1 affected package
dovecot
| Package | 16.04 LTS |
|---|---|
| dovecot | Needs evaluation |