Search CVE reports


Toggle filters

311 – 320 of 498 results


CVE-2016-3099

Medium priority
Vulnerable

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not...

1 affected package

libapache2-mod-nss

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-nss Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2017-5645

Medium priority
Vulnerable

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute...

1 affected package

apache-log4j2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache-log4j2 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-6059

Low priority
Vulnerable

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an...

1 affected package

libapache2-mod-auth-openidc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-openidc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6808

Medium priority
Not affected

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

1 affected package

libapache-mod-jk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-mod-jk — — — — —
Show less packages

CVE-2017-5644

Medium priority
Vulnerable

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

1 affected package

libapache-poi-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-poi-java Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-6807

Medium priority

Some fixes available 1 of 3

mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get...

1 affected package

libapache2-mod-auth-mellon

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-mellon — — — Not affected Not affected
Show less packages

CVE-2017-6413

Medium priority
Vulnerable

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration,...

1 affected package

libapache2-mod-auth-openidc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-openidc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-6062

Medium priority
Vulnerable

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction...

1 affected package

libapache2-mod-auth-openidc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-openidc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-8743

Medium priority

Some fixes available 3 of 4

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages

CVE-2016-2161

Low priority
Fixed

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
Show less packages