Search CVE reports


Toggle filters

321 – 330 of 357 results


CVE-2009-5138

Medium priority
Not affected

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1...

1 affected package

gnutls26

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
Show less packages

CVE-2014-0092

Medium priority

Some fixes available 6 of 9

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2014-1959

Medium priority

Some fixes available 5 of 8

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2013-4487

Medium priority
Ignored

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four...

1 affected package

gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28
Show less packages

CVE-2013-4466

Medium priority
Ignored

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2007-6755

Low priority
Ignored

The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might...

10 affected packages

openssl, mbedtls, openssl098, bouncycastle, gnutls26...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Not affected
mbedtls Not affected
openssl098 Not in release
bouncycastle Not affected
gnutls26 Not in release
gnutls28 Not affected
libgcrypt11 Not in release
nss Not affected
polarssl Not in release
python-crypto Not affected
Show all 10 packages Show less packages

CVE-2013-2116

Medium priority

Some fixes available 6 of 7

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an...

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2013-1619

Medium priority

Some fixes available 5 of 8

The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC...

3 affected packages

gnutls13, gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls13
gnutls26
gnutls28
Show less packages

CVE-2012-3509

Low priority

Some fixes available 2 of 8

Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service...

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils
Show less packages

CVE-2012-2944

Medium priority
Fixed

Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (electric-power outage) via a long string...

1 affected package

nut

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nut
Show less packages