Search CVE reports
1531 – 1540 of 39027 results
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 26.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Not in release |
| mozjs115 | Not in release |
A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but...
1 affected package
gss-ntlmssp
| Package | 26.04 LTS |
|---|---|
| gss-ntlmssp | Needs evaluation |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |
Not in release
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and...
1 affected package
openam
| Package | 26.04 LTS |
|---|---|
| openam | Not in release |