Search CVE reports
11 – 20 of 59834 results
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in...
4 affected packages
php-horde-thrift, python-thrift, ruby-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| python-thrift | Needs evaluation |
| ruby-thrift | — |
| thrift | — |
Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue...
2 affected packages
libthrift-java, thrift
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
| thrift | — |
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |