Search CVE reports


Toggle filters

201 – 210 of 893 results


CVE-2020-26419

Medium priority
Not affected

Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected
Show less packages

CVE-2020-26418

Medium priority
Vulnerable

Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-28030

Medium priority
Ignored

In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Ignored Ignored
Show less packages

CVE-2020-26575

Medium priority
Vulnerable

In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-25866

Medium priority
Not affected

In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Ignored Ignored
Show less packages

CVE-2020-25863

Medium priority
Fixed

In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-25862

Medium priority
Fixed

In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-24890

Medium priority
Not affected

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software...

8 affected packages

darktable, dcraw, exactimage, kodi, libraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Not affected Not affected
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
libraw Not affected Not affected
rawtherapee Not affected Not affected
ufraw Not in release Not affected
xbmc Not in release Not in release
Show all 8 packages Show less packages

CVE-2020-24889

Medium priority
Not affected

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

8 affected packages

libraw, ufraw, darktable, xbmc, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected
ufraw Not in release Not affected
darktable Not affected Not affected
xbmc Not in release Not in release
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
rawtherapee Not affected Not affected
Show all 8 packages Show less packages

CVE-2020-24654

Medium priority
Fixed

In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

1 affected package

ark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ark Fixed Fixed
Show less packages