Search CVE reports


Toggle filters

161 – 170 of 893 results


CVE-2020-35531

Medium priority

Some fixes available 4 of 52

In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
ufraw Not in release Not in release Not in release Not in release Ignored
libraw Not affected Not affected Not affected Fixed Fixed
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35530

Medium priority

Some fixes available 4 of 52

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Fixed Fixed
ufraw Not in release Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2022-24724

Medium priority
Ignored

cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to...

1 affected package

cmark-gfm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cmark-gfm Not affected Not affected Ignored
Show less packages

CVE-2022-0585

Low priority

Some fixes available 1 of 5

Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Not affected
Show less packages

CVE-2022-0586

Medium priority

Some fixes available 4 of 8

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2022-0583

Medium priority

Some fixes available 4 of 8

Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2022-0582

Medium priority

Some fixes available 4 of 8

Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2022-0581

Medium priority

Some fixes available 4 of 8

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2022-21681

Medium priority
Needs evaluation

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs...

1 affected package

node-marked

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-marked Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages

CVE-2022-21680

Medium priority
Needs evaluation

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who...

1 affected package

node-marked

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-marked Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages