Search CVE reports


Toggle filters

21 – 30 of 1351 results


CVE-2024-22233

Medium priority
Not affected

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected Not affected Not affected
Show less packages

CVE-2024-13939

Medium priority
Needs evaluation

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different,...

1 affected package

libstring-compare-constanttime-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstring-compare-constanttime-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-38703

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level...

2 affected packages

asterisk, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-37154

Medium priority
Needs evaluation

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

1 affected package

monitoring-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monitoring-plugins Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-34053

Medium priority
Needs evaluation

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-27585

Medium priority

Some fixes available 4 of 7

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Fixed
pjproject Not in release Not in release Needs evaluation
Show less packages

CVE-2023-20863

Medium priority
Needs evaluation

In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-20861

Medium priority
Needs evaluation

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-20860

Medium priority
Needs evaluation

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC,...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-39269

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media...

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Not in release Needs evaluation Needs evaluation
pjproject Not in release Not in release Needs evaluation
Show less packages