Search CVE reports
1 – 10 of 59834 results
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is...
3 affected packages
grub2, grub2-unsigned, grub2-signed
| Package | 16.04 LTS |
|---|---|
| grub2 | Not affected |
| grub2-unsigned | Needs evaluation |
| grub2-signed | Needs evaluation |
In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it,...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
2 affected packages
php-horde-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| thrift | — |
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
2 affected packages
php-horde-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| thrift | — |
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to...
1 affected package
libthrift-java
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are...
1 affected package
libthrift-java
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue...
2 affected packages
python-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| python-thrift | Needs evaluation |
| thrift | — |
Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to...
2 affected packages
python-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| python-thrift | Needs evaluation |
| thrift | — |
[Unknown description]
1 affected package
epiphany-browser
| Package | 16.04 LTS |
|---|---|
| epiphany-browser | Needs evaluation |
In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |