Search CVE reports
81 – 90 of 59858 results
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written...
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an...
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to...
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing...
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required...
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed...
1 affected package
389-ds-base
| Package | 16.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to...
1 affected package
389-ds-base
| Package | 16.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages....
1 affected package
wss4j
| Package | 16.04 LTS |
|---|---|
| wss4j | Needs evaluation |
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd...
1 affected package
apache2
| Package | 16.04 LTS |
|---|---|
| apache2 | Needs evaluation |
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string...
1 affected package
geopy
| Package | 16.04 LTS |
|---|---|
| geopy | Needs evaluation |