Search CVE reports


Toggle filters

11 – 20 of 30 results


CVE-2021-43797

Medium priority

Some fixes available 8 of 13

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-37137

Medium priority

Some fixes available 8 of 13

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-37136

Medium priority

Some fixes available 8 of 13

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-21409

Medium priority

Some fixes available 8 of 14

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-21295

Medium priority

Some fixes available 8 of 14

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-21290

Medium priority

Some fixes available 9 of 14

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-7238

Medium priority

Some fixes available 2 of 5

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete...

2 affected packages

netty, netty-3.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Not affected Not affected Not affected Needs evaluation
netty-3.9 Not in release Not in release Not in release Not affected
Show less packages

CVE-2020-11612

Medium priority

Some fixes available 3 of 5

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-10707

Negligible priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11612. Reason: This candidate is a reservation duplicate of CVE-2020-11612. Notes: All CVE users should reference CVE-2020-11612 instead of this candidate....

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Not affected
Show less packages

CVE-2019-9518

Medium priority

Some fixes available 1 of 21

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be...

2 affected packages

netty, trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Not affected Not affected Not affected Fixed
trafficserver Needs evaluation Needs evaluation Not affected Needs evaluation
Show less packages