Search CVE reports


Toggle filters

171 – 180 of 498 results


CVE-2020-15389

Low priority
Fixed

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible....

3 affected packages

openjpeg, ghostscript, openjpeg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release Not in release Not in release
ghostscript Not affected Not affected Not affected
openjpeg2 Fixed Fixed Fixed
Show less packages

CVE-2020-11080

Medium priority

Some fixes available 3 of 8

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400...

2 affected packages

nodejs, nghttp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Not affected Not affected Not affected Not affected
nghttp2 Not affected Not affected Fixed Fixed
Show less packages

CVE-2015-8751

Medium priority
Not affected

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

3 affected packages

ghostscript, jasper, netpbm-free

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript
jasper
netpbm-free
Show less packages

CVE-2016-1544

Medium priority
Ignored

nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).

1 affected package

nghttp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nghttp2
Show less packages

CVE-2020-8112

Medium priority

Some fixes available 17 of 64

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

7 affected packages

ghostscript, openjpeg, openjpeg2, blender, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Not affected Not affected Not affected Fixed
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
blender Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Ignored
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
texmaker Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 7 packages Show less packages

CVE-2020-6851

Medium priority

Some fixes available 17 of 69

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

7 affected packages

texmaker, blender, ghostscript, insighttoolkit4, openjpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texmaker Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
blender Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
ghostscript Not affected Not affected Not affected Not affected Fixed
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Ignored
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 7 packages Show less packages

CVE-2011-3349

Medium priority

Some fixes available 1 of 2

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

1 affected package

lightdm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lightdm
Show less packages

CVE-2019-14869

High priority
Fixed

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2007-2841

Medium priority

Some fixes available 5 of 8

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3947. Reason: This candidate is a reservation duplicate of CVE-2007-3947. Notes: All CVE users should reference CVE-2007-3947 instead of this candidate. All...

1 affected package

lighttpd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2005-2352

Medium priority

Not in release

I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript
Show less packages