Search CVE reports


Toggle filters

21 – 30 of 95 results


CVE-2022-28331

Medium priority
Not affected

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

1 affected package

apr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apr Not affected Not affected Not affected
Show less packages

CVE-2022-25147

Medium priority
Fixed

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility...

1 affected package

apr-util

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apr-util Fixed Fixed Fixed
Show less packages

CVE-2022-24963

Medium priority
Fixed

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

1 affected package

apr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apr Fixed Not affected Not affected
Show less packages

CVE-2023-0056

Medium priority
Fixed

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected
Show less packages

CVE-2022-43680

Medium priority

Some fixes available 11 of 94

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

24 affected packages

xmlrpc-c, cableswig, apache2, apr-util, cmake...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
cableswig Not in release Not in release Not in release
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed
ghostscript Not affected Not affected Not affected Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texlive-bin Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ayttm Not in release Not in release Not in release
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
coin3 Not affected Not affected Not affected Needs evaluation
firefox Not affected Not affected Not in release Ignored
gdcm Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
libxmltok Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
smart Not in release Not in release Not affected
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
thunderbird Ignored Ignored Not in release Ignored
vtk Not in release Not in release Not in release
Show all 24 packages Show less packages

CVE-2022-40674

Medium priority

Some fixes available 13 of 118

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

24 affected packages

firefox, cadaver, coin3, gdcm, libxmltok...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Fixed Fixed
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
coin3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
thunderbird Ignored Ignored Not in release Ignored
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed
vnc4 Not in release Not in release Needs evaluation
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release
cableswig Not in release Not in release Not in release
smart Not in release Not in release Needs evaluation
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release
Show all 24 packages Show less packages

CVE-2022-22728

Medium priority
Needs evaluation

A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

1 affected package

libapreq2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapreq2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-0711

Medium priority
Fixed

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Not affected Fixed Not affected
Show less packages

CVE-2022-25315

Medium priority

Some fixes available 19 of 109

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

24 affected packages

ayttm, cadaver, apache2, apr-util, cableswig...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ayttm Not in release Not in release Not in release Not in release
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cableswig Not in release Not in release Not in release Not in release
cmake Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Needs evaluation
expat Fixed Fixed Fixed Fixed
firefox Fixed Fixed Not in release Ignored
gdcm Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not affected
texlive-bin Not affected Not affected Not affected Not affected
thunderbird Ignored Ignored Not in release Ignored
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vnc4 Not in release Not in release Not in release Needs evaluation
vtk Not in release Not in release Not in release Not in release
Show all 24 packages Show less packages

CVE-2022-25314

Medium priority

Some fixes available 17 of 107

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

24 affected packages

thunderbird, ayttm, cableswig, cadaver, apache2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Ignored Ignored Not in release Ignored
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Needs evaluation
insighttoolkit4 Not in release Not affected Not affected Not affected
firefox Fixed Fixed Not in release Ignored
expat Fixed Fixed Fixed Fixed
gdcm Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
libxmltok Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
smart Not in release Not in release Not in release Not affected
texlive-bin Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Needs evaluation
vtk Not in release Not in release Not in release Not in release
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 24 packages Show less packages