Search CVE reports
1051 – 1060 of 57878 results
A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions theĀ regex match can start in the middle of...
1 affected package
mongodb
| Package | 16.04 LTS |
|---|---|
| mongodb | Needs evaluation |
A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused...
3 affected packages
jetty, jetty12, jetty9
| Package | 16.04 LTS |
|---|---|
| jetty | Needs evaluation |
| jetty12 | — |
| jetty9 | Needs evaluation |
A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race...
2 affected packages
jetty12, jetty9
| Package | 16.04 LTS |
|---|---|
| jetty12 | — |
| jetty9 | Needs evaluation |
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute...
1 affected package
libxml2
| Package | 16.04 LTS |
|---|---|
| libxml2 | Needs evaluation |
oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB...
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |
A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
1 affected package
xen
| Package | 16.04 LTS |
|---|---|
| xen | Needs evaluation |