Search CVE reports
111 – 120 of 33257 results
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service...
1 affected package
undertow
| Package | 26.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments...
1 affected package
undertow
| Package | 26.04 LTS |
|---|---|
| undertow | Needs evaluation |
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT...
1 affected package
undertow
| Package | 26.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store...
1 affected package
undertow
| Package | 26.04 LTS |
|---|---|
| undertow | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
[Unknown description]
1 affected package
nltk
| Package | 26.04 LTS |
|---|---|
| nltk | Needs evaluation |
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack...
1 affected package
intel-microcode
| Package | 26.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a...
1 affected package
intel-microcode
| Package | 26.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high...
1 affected package
intel-microcode
| Package | 26.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |