Search CVE reports
1701 – 1710 of 47890 results
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 22.04 LTS |
|---|---|
| emacs | Needs evaluation |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Not in release |
| emacs25 | Not in release |
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An...
1 affected package
cpio
| Package | 22.04 LTS |
|---|---|
| cpio | Vulnerable |
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled...
1 affected package
cpio
| Package | 22.04 LTS |
|---|---|
| cpio | Vulnerable |
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar...
1 affected package
cpio
| Package | 22.04 LTS |
|---|---|
| cpio | Vulnerable |
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle...
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when...
1 affected package
389-ds-base
| Package | 22.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
Not in release
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method...
1 affected package
keras
| Package | 22.04 LTS |
|---|---|
| keras | Not in release |
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 22.04 LTS |
|---|---|
| expat | Needs evaluation |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Not in release |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Not affected |
| ayttm | Not in release |
| cableswig | Not in release |
| coin3 | Not affected |
| matanza | Ignored |
| tdom | Needs evaluation |
| vtk | Not in release |
| smart | Not in release |
| firefox | Not affected |
| thunderbird | Not affected |
| libxmltok | Needs evaluation |
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation...
1 affected package
gst-plugins-ugly1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-ugly1.0 | Needs evaluation |
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a...
1 affected package
gst-plugins-bad1.0
| Package | 22.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |