Search CVE reports
1 – 10 of 95 results
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to...
4 affected packages
h2o, haproxy, lighttpd, varnish
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
h2o | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
haproxy | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
lighttpd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
varnish | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.
1 affected package
haproxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
haproxy | Fixed | Fixed | Not affected | Not affected |
Some fixes available 4 of 76
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Needs evaluation |
ayttm | Not in release | Not in release | Not in release | — |
cableswig | Not in release | Not in release | Not in release | — |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Needs evaluation | Needs evaluation |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | — |
smart | Not in release | Not in release | Not in release | Needs evaluation |
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
libxmltok | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
expat | Fixed | Fixed | Ignored | Ignored |
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set...
1 affected package
haproxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
haproxy | Fixed | Not affected | Not affected | Not affected |
Some fixes available 7 of 68
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
expat | Fixed | Fixed | Fixed | Fixed |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Needs evaluation |
ayttm | Not in release | Not in release | Not in release | — |
cableswig | Not in release | Not in release | Not in release | — |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | — |
smart | Not in release | Not in release | Not in release | Needs evaluation |
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
libxmltok | Not affected | Not affected | Not affected | Not affected |
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
1 affected package
haproxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
haproxy | Not affected | Not affected | Not affected | Not affected |
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
1 affected package
haproxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
haproxy | Not affected | Not affected | Not affected | Not affected |
Some fixes available 6 of 67
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
tdom, apache2, apr-util, cmake, ghostscript...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Needs evaluation |
ayttm | Not in release | Not in release | Not in release | — |
cableswig | Not in release | Not in release | Not in release | — |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
vtk | Not in release | Not in release | Not in release | — |
smart | Not in release | Not in release | Not in release | Needs evaluation |
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
libxmltok | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
Some fixes available 13 of 74
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Needs evaluation |
ayttm | Not in release | Not in release | Not in release | — |
cableswig | Not in release | Not in release | Not in release | — |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | — |
smart | Not in release | Not in release | Not in release | Needs evaluation |
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
libxmltok | Fixed | Fixed | Fixed | Fixed |
expat | Fixed | Fixed | Fixed | Fixed |
Some fixes available 13 of 74
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Needs evaluation |
ayttm | Not in release | Not in release | Not in release | — |
cableswig | Not in release | Not in release | Not in release | — |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | — |
smart | Not in release | Not in release | Not in release | Needs evaluation |
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
libxmltok | Fixed | Fixed | Fixed | Fixed |