Search CVE reports


Toggle filters

191 – 200 of 566 results

Status is adjusted based on your filters.


CVE-2022-1343

Medium priority
Not affected

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in...

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Not affected
openssl1.0 Not in release
Show less packages

CVE-2022-1292

Medium priority
Fixed

The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an...

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Fixed
openssl1.0 Not in release
Show less packages

CVE-2021-43085

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Not affected
openssl1.0 Not in release
Show less packages

CVE-2022-0778

High priority
Fixed

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public...

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Fixed
openssl1.0 Not in release
Show less packages

CVE-2021-36368

Medium priority
Not affected

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None...

2 affected packages

openssh, openssh-ssh1

Package 14.04 LTS
openssh Not affected
openssh-ssh1 Not in release
Show less packages

CVE-2021-4160

Low priority
Not affected

There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack...

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Not affected
openssl1.0 Not in release
Show less packages

CVE-2022-22747

Low priority
Fixed

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5,...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 14.04 LTS
firefox —
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
nss Fixed
thunderbird Not in release
Show all 7 packages Show less packages

CVE-2021-4044

Medium priority
Not affected

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory)....

4 affected packages

edk2, nodejs, openssl, openssl1.0

Package 14.04 LTS
edk2 Not in release
nodejs Not affected
openssl Not affected
openssl1.0 Not in release
Show less packages

CVE-2021-43527

High priority
Fixed

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME,...

2 affected packages

nss, thunderbird

Package 14.04 LTS
nss Fixed
thunderbird Not in release
Show less packages

CVE-2021-41617

Low priority
Vulnerable

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and...

2 affected packages

openssh, openssh-ssh1

Package 14.04 LTS
openssh Vulnerable
openssh-ssh1 Not in release
Show less packages