Search CVE reports
891 – 900 of 36525 results
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider...
1 affected package
curl
| Package | 24.04 LTS |
|---|---|
| curl | Not affected |
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
1 affected package
csync2
| Package | 24.04 LTS |
|---|---|
| csync2 | Needs evaluation |
Not in release
After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency...
1 affected package
mongodb
| Package | 24.04 LTS |
|---|---|
| mongodb | Not in release |
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill...
1 affected package
malcontent
| Package | 24.04 LTS |
|---|---|
| malcontent | Not affected |
Not in release
[Unknown description]
1 affected package
botan3
| Package | 24.04 LTS |
|---|---|
| botan3 | Not in release |