Search CVE reports
1011 – 1020 of 48104 results
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero...
1 affected package
async-http-client
| Package | 24.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and...
1 affected package
async-http-client
| Package | 24.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory...
1 affected package
libxml2
| Package | 24.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet...
1 affected package
mariadb-connector-java
| Package | 24.04 LTS |
|---|---|
| mariadb-connector-java | Needs evaluation |
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote...
1 affected package
redis
| Package | 24.04 LTS |
|---|---|
| redis | Needs evaluation |
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to...
1 affected package
flatpak-builder
| Package | 24.04 LTS |
|---|---|
| flatpak-builder | Needs evaluation |
[Incomplete fix of CVE-2018-10900]
1 affected package
network-manager-vpnc
| Package | 24.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
[username newline injection reaches a root password helper]
1 affected package
network-manager-vpnc
| Package | 24.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
[credential newline injection permits local root code execution]
1 affected package
network-manager-fortisslvpn
| Package | 24.04 LTS |
|---|---|
| network-manager-fortisslvpn | Needs evaluation |
[profile data reaches root pppd pty shell]
1 affected package
network-manager-sstp
| Package | 24.04 LTS |
|---|---|
| network-manager-sstp | Needs evaluation |