Search CVE reports
371 – 380 of 42038 results
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
1 affected package
openvpn
| Package | 24.04 LTS |
|---|---|
| openvpn | Needs evaluation |
Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution...
1 affected package
libdate-manip-perl
| Package | 24.04 LTS |
|---|---|
| libdate-manip-perl | Needs evaluation |
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character...
1 affected package
libdate-manip-perl
| Package | 24.04 LTS |
|---|---|
| libdate-manip-perl | Needs evaluation |
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 24.04 LTS |
|---|---|
| php5 | Not in release |
| php7.0 | Not in release |
| php7.2 | Not in release |
| php7.4 | Not in release |
| php8.1 | Not in release |
| php8.3 | Needs evaluation |
| php8.5 | Not in release |
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 24.04 LTS |
|---|---|
| php5 | Not in release |
| php7.0 | Not in release |
| php7.2 | Not in release |
| php7.4 | Not in release |
| php8.1 | Not in release |
| php8.3 | Needs evaluation |
| php8.5 | Not in release |
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 24.04 LTS |
|---|---|
| php5 | Not in release |
| php7.0 | Not in release |
| php7.2 | Not in release |
| php7.4 | Not in release |
| php8.1 | Not in release |
| php8.3 | Needs evaluation |
| php8.5 | Not in release |
Not in release
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....
1 affected package
dogtag-pki
| Package | 24.04 LTS |
|---|---|
| dogtag-pki | Not in release |
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or...
1 affected package
nodejs
| Package | 24.04 LTS |
|---|---|
| nodejs | Needs evaluation |
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
1 affected package
nodejs
| Package | 24.04 LTS |
|---|---|
| nodejs | Needs evaluation |
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability...
1 affected package
nodejs
| Package | 24.04 LTS |
|---|---|
| nodejs | Needs evaluation |