Search CVE reports
81 – 90 of 50631 results
fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents...
1 affected package
fsspec
| Package | 20.04 LTS |
|---|---|
| fsspec | Needs evaluation |
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
1 affected package
ejabberd
| Package | 20.04 LTS |
|---|---|
| ejabberd | Needs evaluation |
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender...
1 affected package
logback
| Package | 20.04 LTS |
|---|---|
| logback | Needs evaluation |
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can...
1 affected package
apache-directory-api
| Package | 20.04 LTS |
|---|---|
| apache-directory-api | Needs evaluation |