Search CVE reports


Toggle filters

291 – 300 of 357 results


CVE-2016-6131

Low priority

Some fixes available 8 of 84

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.

8 affected packages

binutils, gdb, ht, libiberty, valgrind...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Not affected Not affected Not affected Not affected
gdb Not affected Not affected Not affected Not affected
ht Not affected Not affected Not affected Not affected
libiberty Not affected Not affected Not affected Not affected
valgrind Not affected Not affected Not affected Not affected
binutils-h8300-hms Vulnerable Vulnerable Vulnerable Vulnerable
gcc-h8300-hms Vulnerable Vulnerable Vulnerable Vulnerable
nescc Not in release Vulnerable Vulnerable Vulnerable
Show all 8 packages Show less packages

CVE-2017-5337

Medium priority

Some fixes available 9 of 10

Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages

CVE-2017-5336

Medium priority

Some fixes available 9 of 10

Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages

CVE-2017-5335

Medium priority

Some fixes available 9 of 10

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages

CVE-2017-5334

Medium priority

Some fixes available 7 of 8

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages

CVE-2016-8610

Low priority

Some fixes available 13 of 15

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw...

4 affected packages

gnutls28, openssl098, gnutls26, openssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Not affected
openssl098 Not in release
gnutls26 Not in release
openssl Fixed
Show less packages

CVE-2016-7444

Low priority
Fixed

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Not affected
Show less packages

CVE-2016-2183

Low priority

Some fixes available 23 of 25

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain...

8 affected packages

gnutls26, gnutls28, nss, openjdk-6, openjdk-7...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Not affected
nss Fixed
openjdk-6 Not in release
openjdk-7 Not in release
openjdk-8 Not affected
openssl Fixed
openssl098 Not in release
Show all 8 packages Show less packages

CVE-2015-7575

Medium priority

Some fixes available 38 of 44

Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol...

12 affected packages

firefox, gnutls26, gnutls28, mbedtls, nss...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
gnutls26 Not in release
gnutls28 Not affected
mbedtls Not affected
nss Not affected
openjdk-6 Not in release
openjdk-7 Not in release
openjdk-8 Not affected
openssl Not affected
openssl098 Not in release
polarssl Not in release
thunderbird Fixed
Show all 12 packages Show less packages

CVE-2015-8313

Medium priority
Fixed

GnuTLS incorrectly validates the first byte of padding in CBC modes

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages