Search CVE reports
1161 – 1170 of 59834 results
Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web...
6 affected packages
tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11
| Package | 16.04 LTS |
|---|---|
| tomcat6 | Not affected |
| tomcat7 | Needs evaluation |
| tomcat8 | Needs evaluation |
| tomcat9 | — |
| tomcat10 | — |
| tomcat11 | — |
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through...
6 affected packages
tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11
| Package | 16.04 LTS |
|---|---|
| tomcat6 | Not affected |
| tomcat7 | Needs evaluation |
| tomcat8 | Needs evaluation |
| tomcat9 | — |
| tomcat10 | — |
| tomcat11 | — |
A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths...
1 affected package
jackson-databind
| Package | 16.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for...
1 affected package
jackson-databind
| Package | 16.04 LTS |
|---|---|
| jackson-databind | Needs evaluation |
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the...
1 affected package
jackson-core
| Package | 16.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
[Unknown description]
1 affected package
zbar
| Package | 16.04 LTS |
|---|---|
| zbar | Needs evaluation |
[Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
[mdtls discards the peer-identity verification result]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
[Unknown description]
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |