Search CVE reports


Toggle filters

411 – 420 of 453 results


CVE-2007-5770

Low priority
Fixed

The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent...

2 affected packages

libopenssl-ruby, ruby1.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenssl-ruby
ruby1.8
Show less packages

CVE-2007-5794

Low priority
Ignored

Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection....

1 affected package

libnss-ldap

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnss-ldap
Show less packages

CVE-2007-3102

Low priority
Not affected

Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted...

1 affected package

openssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh
Show less packages

CVE-2007-5536

Low priority
Not affected

Unspecified vulnerability in OpenSSL before A.00.09.07l on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to cause a denial of service via unspecified vectors.

2 affected packages

openssl, openssl097

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl
openssl097
Show less packages

CVE-2007-4995

Low priority

Some fixes available 4 of 7

Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.

2 affected packages

openssl, openssl097

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl
openssl097
Show less packages

CVE-2007-5162

Low priority
Fixed

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request,...

2 affected packages

libopenssl-ruby, ruby1.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenssl-ruby
ruby1.8
Show less packages

CVE-2007-5135

Medium priority

Some fixes available 8 of 11

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. ...

2 affected packages

openssl, openssl097

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl
openssl097
Show less packages

CVE-2007-4752

Low priority
Fixed

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to...

1 affected package

openssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh
Show less packages

CVE-2007-3108

Negligible priority

Some fixes available 8 of 11

The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.

2 affected packages

openssl, openssl097

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl
openssl097
Show less packages

CVE-2007-2768

Negligible priority
Ignored

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to...

1 affected package

openssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh
Show less packages