Search CVE reports


Toggle filters

121 – 130 of 306 results


CVE-2019-0215

Medium priority
Not affected

In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Not affected
Show less packages

CVE-2019-0211

High priority
Fixed

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages

CVE-2019-0197

Low priority

Some fixes available 2 of 3

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages

CVE-2019-0196

Low priority
Fixed

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages

CVE-2019-0190

Medium priority
Not affected

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Not affected
Show less packages

CVE-2018-8011

Medium priority
Not affected

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Not affected
Show less packages

CVE-2018-20843

Low priority

Some fixes available 25 of 121

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...

32 affected packages

coin3, vnc4, xmlrpc-c, libxmltok, audacity...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coin3 Not affected Not affected Not affected Vulnerable
vnc4 Not in release Not in release Not in release Vulnerable
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Fixed Fixed Fixed Fixed
audacity Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
expat Fixed Fixed Fixed Fixed
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
wxwidgets2.8 Not in release Not in release Not in release Not in release
wxwidgets2.6 Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
libparagui1.1 Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kompozer Not in release Not in release Not in release Not in release
insighttoolkit Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
simgear Not affected Not affected Not affected Not affected
tdom Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release Not in release
smart Not in release Not in release Not in release Not affected
firefox Not affected Not affected Not in release Not affected
thunderbird Not affected Not affected Not in release Not affected
Show all 32 packages Show less packages

CVE-2018-17199

Low priority
Fixed

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages

CVE-2018-17189

Low priority
Fixed

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages

CVE-2018-1333

Low priority
Fixed

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed
Show less packages