Search CVE reports
1081 – 1090 of 59781 results
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |
Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled...
1 affected package
pgbouncer
| Package | 16.04 LTS |
|---|---|
| pgbouncer | Needs evaluation |
Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving...
1 affected package
pgbouncer
| Package | 16.04 LTS |
|---|---|
| pgbouncer | Needs evaluation |
Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report...
1 affected package
pgbouncer
| Package | 16.04 LTS |
|---|---|
| pgbouncer | Needs evaluation |
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse...
1 affected package
alsa-lib
| Package | 16.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |
alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size...
1 affected package
alsa-lib
| Package | 16.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |