Search CVE reports


Toggle filters

211 – 220 of 893 results


CVE-2020-17498

Medium priority
Fixed

In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Not affected
Show less packages

CVE-2020-16116

Medium priority

Some fixes available 2 of 3

In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

1 affected package

ark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ark Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-15466

Low priority

Some fixes available 1 of 2

In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Not affected
Show less packages

CVE-2020-15503

Low priority

Some fixes available 2 of 71

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs...

8 affected packages

kodi, libraw, rawtherapee, dcraw, exactimage...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Fixed Fixed
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
ufraw Not in release Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2020-5238

Low priority
Needs evaluation

The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a...

5 affected packages

r-cran-commonmark, ruby-commonmarker, cmark-gfm, python-cmarkgfm, haskell-cmark-gfm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
r-cran-commonmark Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
ruby-commonmarker Not affected Not affected Not affected Ignored Not in release
cmark-gfm Not affected Not affected Not affected Ignored Not in release
python-cmarkgfm Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
haskell-cmark-gfm Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
Show less packages

CVE-2020-15365

Medium priority
Needs evaluation

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

8 affected packages

xbmc, kodi, darktable, libraw, ufraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xbmc Not in release Not in release Not in release Not in release Not in release
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2020-13164

Low priority

Some fixes available 4 of 5

In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-11888

Medium priority
Ignored

python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.

1 affected package

python-markdown2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-markdown2 Not affected Not affected Not affected Ignored Not in release
Show less packages

CVE-2020-11647

Medium priority
Vulnerable

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9431

Low priority
Vulnerable

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Not affected Not affected Vulnerable
Show less packages