Search CVE reports


Toggle filters

331 – 340 of 390 results


CVE-2016-2183

Low priority

Some fixes available 23 of 25

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain...

8 affected packages

gnutls26, gnutls28, nss, openjdk-6, openjdk-7...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Not affected
nss Fixed
openjdk-6 Not in release
openjdk-7 Not in release
openjdk-8 Not affected
openssl Fixed
openssl098 Not in release
Show all 8 packages Show less packages

CVE-2015-7575

Medium priority

Some fixes available 38 of 44

Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol...

12 affected packages

firefox, gnutls26, gnutls28, mbedtls, nss...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
gnutls26 Not in release
gnutls28 Not affected
mbedtls Not affected
nss Not affected
openjdk-6 Not in release
openjdk-7 Not in release
openjdk-8 Not affected
openssl Not affected
openssl098 Not in release
polarssl Not in release
thunderbird Fixed
Show all 12 packages Show less packages

CVE-2015-8313

Medium priority
Fixed

GnuTLS incorrectly validates the first byte of padding in CBC modes

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2015-5218

Low priority
Ignored

Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.

2 affected packages

bsdmainutils, util-linux

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bsdmainutils Not affected Not affected Not affected
util-linux Not affected Not affected Not affected
Show less packages

CVE-2015-6251

Medium priority
Fixed

Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages

CVE-2015-4000

Medium priority

Some fixes available 48 of 55

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks...

11 affected packages

gnutls26, apache2, firefox, gnutls28, nss...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
apache2 Not affected
firefox Fixed
gnutls28 Not affected
nss Fixed
openjdk-6 Not in release
openjdk-7 Not in release
openjdk-8 Not affected
openssl Not affected
openssl098 Not in release
thunderbird Fixed
Show all 11 packages Show less packages

CVE-2015-3308

Low priority
Fixed

Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2015-2091

Medium priority
Ignored

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attackers to spoof clients via a crafted certificate.

1 affected package

mod-gnutls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mod-gnutls Not affected
Show less packages

CVE-2015-0282

Medium priority

Some fixes available 3 of 5

GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
gnutls28
Show less packages

CVE-2015-0294

Low priority

Some fixes available 13 of 15

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

2 affected packages

gnutls26, gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26 Not in release
gnutls28 Fixed
Show less packages