Search CVE reports
1 – 10 of 63 results
(An attacker that connects to an open Erlang TCP port that uses the ine ...)
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ...)
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ...)
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the...
2 affected packages
erlang-cowboy, rabbitmq-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang-cowboy | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| rabbitmq-server | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and...
2 affected packages
erlang-cowlib, rabbitmq-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang-cowlib | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| rabbitmq-server | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the...
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending...
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed...
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5...
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer...
1 affected package
erlang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| erlang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |