CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreOct 27, 2025 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
8Apache CanonicalDebian+5 more14Clustered Data Ontap Debian LinuxEnterprise Linux+11 moreNov 21, 2024 Apr 8, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing config...Show more |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreNov 21, 2024 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
7Canonical DebianHaxx+4 more16Active Iq Unified Manager Clustered Data OntapCommunications Operations Monitor+13 moreNov 21, 2024 Feb 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates th...Show more |
2Apache Oracle5Enterprise Manager Ops Center Hospitality Guest AccessHttp Server+2 moreNov 21, 2024 Jan 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only trigge...Show more |
5Apache CanonicalDebian+2 more6Debian Linux Enterprise Manager Ops CenterHttp Server+3 moreNov 21, 2024 Jan 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry t...Show more |
7Apache CanonicalDebian+4 more12Debian Linux Enterprise Manager Ops CenterFedora+9 moreNov 21, 2024 Jan 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more |
2Dell Oracle12Application Testing Suite BsafeCommunications Analytics+9 moreNov 21, 2024 Nov 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Se...Show more |
7Canonical DebianNodejs+4 more20Api Gateway Application ServerDebian Linux+17 moreNov 21, 2024 Nov 15, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. |
6Canonical DebianNetapp+3 more19Api Gateway Cloud BackupCn1610 Firmware+16 moreNov 21, 2024 Oct 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
3Debian OracleVmware40Agile Plm Communications Brm Elastic Charging EngineCommunications Converged Application Server Service Controller+37 moreNov 21, 2024 Oct 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through t...Show more |
5Apache CanonicalNetapp+2 more9Enterprise Linux Enterprise Manager Ops CenterHospitality Guest Access+6 moreNov 21, 2024 Sep 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2...Show more |
2Dell Oracle13Application Testing Suite BsafeBsafe Crypto C+10 moreNov 21, 2024 Sep 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when pa...Show more |
2Dell Oracle12Application Testing Suite BsafeCommunications Analytics+9 moreNov 21, 2024 Aug 31, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryp...Show more |
2Dell Oracle13Application Testing Suite BsafeBsafe Crypto C+10 moreNov 21, 2024 Aug 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability whe...Show more |
2Dell Oracle12Application Testing Suite BsafeCommunications Analytics+9 moreNov 21, 2024 Aug 31, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in...Show more |
2Dell Oracle12Application Testing Suite BsafeCommunications Analytics+9 moreNov 21, 2024 Aug 31, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service. |
1Oracle 1Enterprise Manager Ops Center Nov 21, 2024 Jul 18, 2018 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent: Networking). The supported version that is affected is 12.2.2. Easily exploitable vulnerability allo...Show more |
3Debian OracleVmware28Agile Product Lifecycle Management Application Testing SuiteCommunications Network Integrity+25 moreNov 21, 2024 Jun 25, 2018 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpRespons...Show more |