Search CVE reports
1 – 10 of 49410 results
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This...
1 affected package
freetype
| Package | 24.04 LTS |
|---|---|
| freetype | Needs evaluation |
Not in release
[Unknown description]
1 affected package
podman
| Package | 24.04 LTS |
|---|---|
| podman | Not in release |
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests...
1 affected package
apache2
| Package | 24.04 LTS |
|---|---|
| apache2 | Needs evaluation |
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |
[Unknown description]
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required...
1 affected package
wss4j
| Package | 24.04 LTS |
|---|---|
| wss4j | Needs evaluation |