Search CVE reports
931 – 940 of 39983 results
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Vulnerable |
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent...
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Vulnerable |
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or...
1 affected package
libspring-java
| Package | 20.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows...
1 affected package
libspring-java
| Package | 20.04 LTS |
|---|---|
| libspring-java | Needs evaluation |
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from...
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced...
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Needs evaluation |
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
1 affected package
exim4
| Package | 20.04 LTS |
|---|---|
| exim4 | Not affected |
cross-proxy Digest auth state leak
1 affected package
curl
| Package | 20.04 LTS |
|---|---|
| curl | Needs evaluation |
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods...
1 affected package
libtext-csv-xs-perl
| Package | 20.04 LTS |
|---|---|
| libtext-csv-xs-perl | Needs evaluation |