Search CVE reports


Toggle filters

11 – 15 of 15 results


CVE-2015-2774

Low priority

Some fixes available 1 of 6

Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
erlang Not affected
Show less packages

CVE-2014-1693

Low priority

Some fixes available 1 of 5

Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6)...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
erlang Not affected
Show less packages

CVE-2011-0766

Low priority
Ignored

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
erlang
Show less packages

CVE-2009-0130

Medium priority
Ignored

** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
erlang
Show less packages

CVE-2008-2371

Low priority
Fixed

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a...

3 affected packages

erlang, pcre3, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
erlang
pcre3
php5
Show less packages