Search CVE reports
1321 – 1330 of 1377 results
Some fixes available 12 of 49
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
32 affected packages
linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| linux | — | — | — | — | — |
| linux-armadaxp | — | — | — | — | — |
| linux-aws | — | — | — | — | — |
| linux-ec2 | — | — | — | — | — |
| linux-flo | — | — | — | — | — |
| linux-fsl-imx51 | — | — | — | — | — |
| linux-gke | — | — | — | — | — |
| linux-goldfish | — | — | — | — | — |
| linux-grouper | — | — | — | — | — |
| linux-hwe | — | — | — | — | — |
| linux-hwe-edge | — | — | — | — | — |
| linux-linaro-omap | — | — | — | — | — |
| linux-linaro-shared | — | — | — | — | — |
| linux-linaro-vexpress | — | — | — | — | — |
| linux-lts-backport-maverick | — | — | — | — | — |
| linux-lts-backport-natty | — | — | — | — | — |
| linux-lts-backport-oneiric | — | — | — | — | — |
| linux-lts-quantal | — | — | — | — | — |
| linux-lts-raring | — | — | — | — | — |
| linux-lts-trusty | — | — | — | — | — |
| linux-lts-utopic | — | — | — | — | — |
| linux-lts-vivid | — | — | — | — | — |
| linux-lts-wily | — | — | — | — | — |
| linux-lts-xenial | — | — | — | — | — |
| linux-maguro | — | — | — | — | — |
| linux-mako | — | — | — | — | — |
| linux-manta | — | — | — | — | — |
| linux-mvl-dove | — | — | — | — | — |
| linux-qcm-msm | — | — | — | — | — |
| linux-raspi2 | — | — | — | — | — |
| linux-snapdragon | — | — | — | — | — |
| linux-ti-omap4 | — | — | — | — | — |
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow...
1 affected package
libspring-security-2.0-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libspring-security-2.0-java | — | — | — | — | Not in release |
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting...
1 affected package
libspring-security-2.0-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libspring-security-2.0-java | — | — | — | — | — |
Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via...
1 affected package
libspring-security-2.0-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libspring-security-2.0-java | — | — | — | — | — |
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain...
1 affected package
libspring-2.5-java
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libspring-2.5-java | — | — | — | — | — |
Some fixes available 3 of 22
The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.
14 affected packages
linux, linux-armadaxp, linux-ec2, linux-fsl-imx51, linux-linaro-omap...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| linux | — | — | — | — | — |
| linux-armadaxp | — | — | — | — | — |
| linux-ec2 | — | — | — | — | — |
| linux-fsl-imx51 | — | — | — | — | — |
| linux-linaro-omap | — | — | — | — | — |
| linux-linaro-shared | — | — | — | — | — |
| linux-linaro-vexpress | — | — | — | — | — |
| linux-lts-backport-maverick | — | — | — | — | — |
| linux-lts-backport-oneiric | — | — | — | — | — |
| linux-lts-quantal | — | — | — | — | — |
| linux-lts-raring | — | — | — | — | — |
| linux-mvl-dove | — | — | — | — | — |
| linux-qcm-msm | — | — | — | — | — |
| linux-ti-omap4 | — | — | — | — | — |
Some fixes available 2 of 3
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
1 affected package
python-keyring
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-keyring | — | — | — | — | — |
GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown...
1 affected package
gnome-keyring
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| gnome-keyring | — | — | — | — | — |
Some fixes available 12 of 48
The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
32 affected packages
linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| linux | — | — | — | — | — |
| linux-armadaxp | — | — | — | — | — |
| linux-aws | — | — | — | — | — |
| linux-ec2 | — | — | — | — | — |
| linux-flo | — | — | — | — | — |
| linux-fsl-imx51 | — | — | — | — | — |
| linux-gke | — | — | — | — | — |
| linux-goldfish | — | — | — | — | — |
| linux-grouper | — | — | — | — | — |
| linux-hwe | — | — | — | — | — |
| linux-hwe-edge | — | — | — | — | — |
| linux-linaro-omap | — | — | — | — | — |
| linux-linaro-shared | — | — | — | — | — |
| linux-linaro-vexpress | — | — | — | — | — |
| linux-lts-backport-maverick | — | — | — | — | — |
| linux-lts-backport-natty | — | — | — | — | — |
| linux-lts-backport-oneiric | — | — | — | — | — |
| linux-lts-quantal | — | — | — | — | — |
| linux-lts-raring | — | — | — | — | — |
| linux-lts-trusty | — | — | — | — | — |
| linux-lts-utopic | — | — | — | — | — |
| linux-lts-vivid | — | — | — | — | — |
| linux-lts-wily | — | — | — | — | — |
| linux-lts-xenial | — | — | — | — | — |
| linux-maguro | — | — | — | — | — |
| linux-mako | — | — | — | — | — |
| linux-manta | — | — | — | — | — |
| linux-mvl-dove | — | — | — | — | — |
| linux-qcm-msm | — | — | — | — | — |
| linux-raspi2 | — | — | — | — | — |
| linux-snapdragon | — | — | — | — | — |
| linux-ti-omap4 | — | — | — | — | — |
Some fixes available 7 of 34
The __request_module function in kernel/kmod.c in the Linux kernel before 3.4 does not set a certain killable attribute, which allows local users to cause a denial of service (memory consumption) via a crafted application.
32 affected packages
linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| linux | — | — | — | — | — |
| linux-armadaxp | — | — | — | — | — |
| linux-aws | — | — | — | — | — |
| linux-ec2 | — | — | — | — | — |
| linux-flo | — | — | — | — | — |
| linux-fsl-imx51 | — | — | — | — | — |
| linux-gke | — | — | — | — | — |
| linux-goldfish | — | — | — | — | — |
| linux-grouper | — | — | — | — | — |
| linux-hwe | — | — | — | — | — |
| linux-hwe-edge | — | — | — | — | — |
| linux-linaro-omap | — | — | — | — | — |
| linux-linaro-shared | — | — | — | — | — |
| linux-linaro-vexpress | — | — | — | — | — |
| linux-lts-backport-maverick | — | — | — | — | — |
| linux-lts-backport-natty | — | — | — | — | — |
| linux-lts-backport-oneiric | — | — | — | — | — |
| linux-lts-quantal | — | — | — | — | — |
| linux-lts-raring | — | — | — | — | — |
| linux-lts-trusty | — | — | — | — | — |
| linux-lts-utopic | — | — | — | — | — |
| linux-lts-vivid | — | — | — | — | — |
| linux-lts-wily | — | — | — | — | — |
| linux-lts-xenial | — | — | — | — | — |
| linux-maguro | — | — | — | — | — |
| linux-mako | — | — | — | — | — |
| linux-manta | — | — | — | — | — |
| linux-mvl-dove | — | — | — | — | — |
| linux-qcm-msm | — | — | — | — | — |
| linux-raspi2 | — | — | — | — | — |
| linux-snapdragon | — | — | — | — | — |
| linux-ti-omap4 | — | — | — | — | — |