Search CVE reports


Toggle filters

191 – 200 of 498 results


CVE-2019-14812

Medium priority
Fixed

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-14811

Medium priority
Fixed

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-9513

Medium priority

Some fixes available 15 of 25

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes...

3 affected packages

nghttp2, nginx, nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nghttp2 Not affected Not affected Not affected Fixed
nginx Fixed Fixed Fixed Fixed
nodejs Not affected Not affected Not affected Ignored
Show less packages

CVE-2019-9511

Medium priority

Some fixes available 15 of 25

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over...

3 affected packages

nghttp2, nginx, nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nghttp2 Not affected Not affected Not affected Fixed
nginx Fixed Fixed Fixed Fixed
nodejs Not affected Not affected Not affected Ignored
Show less packages

CVE-2019-10216

Medium priority
Fixed

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-13623

Medium priority

Not in release

In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to...

1 affected package

ghidra

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghidra Not in release
Show less packages

CVE-2019-13453

Medium priority
Fixed

Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().

2 affected packages

flightcrew, zipios++

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightcrew Fixed
zipios++ Fixed
Show less packages

CVE-2019-13241

Medium priority
Fixed

FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.

1 affected package

flightcrew

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightcrew Fixed
Show less packages

CVE-2019-13032

Low priority
Fixed

An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects...

1 affected package

flightcrew

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightcrew Fixed
Show less packages

CVE-2019-12973

Low priority

Some fixes available 15 of 89

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to...

9 affected packages

blender, emscripten, gdcm, ghostscript, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
blender Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
emscripten Ignored Ignored Ignored Not in release Ignored
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Ignored
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
texmaker Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 9 packages Show less packages