Search CVE reports
151 – 160 of 29048 results
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Fixed |
Some fixes available 1 of 2
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with...
11 affected packages
mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...
| Package | 26.04 LTS |
|---|---|
| mysql-5.5 | Not in release |
| mysql-5.7 | Not in release |
| mysql-8.0 | Not in release |
| mysql-8.4 | Fixed |
| mariadb | Needs evaluation |
| mariadb-10.0 | Not in release |
| mariadb-10.1 | Not in release |
| mariadb-10.3 | Not in release |
| mariadb-10.6 | Not in release |
| percona-xtradb-cluster-5.6 | Not in release |
| percona-server-5.6 | Not in release |
(NGINX Open Source has a vulnerability in the ngx_http_v3_modulemodule. ...)
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Not affected |
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2...
1 affected package
nginx
| Package | 26.04 LTS |
|---|---|
| nginx | Fixed |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in...
1 affected package
openexr
| Package | 26.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl()...
1 affected package
openexr
| Package | 26.04 LTS |
|---|---|
| openexr | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access...
1 affected package
coturn
| Package | 26.04 LTS |
|---|---|
| coturn | Needs evaluation |
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap...
1 affected package
libssh2
| Package | 26.04 LTS |
|---|---|
| libssh2 | Needs evaluation |
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation...
1 affected package
coturn
| Package | 26.04 LTS |
|---|---|
| coturn | Needs evaluation |
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger...
1 affected package
nilfs-tools
| Package | 26.04 LTS |
|---|---|
| nilfs-tools | Needs evaluation |