Search CVE reports
1731 – 1740 of 45973 results
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Some fixes available 2 of 3
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Fixed |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Not in release |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a...
1 affected package
openexr
| Package | 24.04 LTS |
|---|---|
| openexr | Needs evaluation |
Some fixes available 2 of 3
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Fixed |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | Not in release |
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 24.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | Not in release |