Search CVE reports


Toggle filters

131 – 140 of 257 results


CVE-2020-6851

Medium priority

Some fixes available 17 of 69

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

7 affected packages

texmaker, blender, ghostscript, insighttoolkit4, openjpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texmaker Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
blender Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
ghostscript Not affected Not affected Not affected Not affected Fixed
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Ignored
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 7 packages Show less packages

CVE-2019-14869

High priority
Fixed

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2005-2352

Medium priority

Not in release

I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript
Show less packages

CVE-2018-21010

Medium priority

Some fixes available 2 of 54

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

8 affected packages

qtwebengine-opensource-src, blender, gdcm, ghostscript, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
blender Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Ignored
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected Fixed
texmaker Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2019-15903

Medium priority

Some fixes available 62 of 188

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a...

32 affected packages

insighttoolkit4, cadaver, insighttoolkit, audacity, ayttm...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
cadaver Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
insighttoolkit Not in release Not in release Not in release Not in release Not in release
audacity Not affected Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release Not in release
chromium-browser Fixed Fixed Fixed Fixed Fixed
sitecopy Needs evaluation Not in release Needs evaluation Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
coin3 Not affected Not affected Not affected Not affected Vulnerable
firefox Fixed Fixed Fixed Fixed Fixed
matanza Ignored Ignored Ignored Ignored Ignored
smart Not in release Not in release Not in release Not in release Not affected
libxmltok Not in release Fixed Fixed Fixed Fixed
tdom Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
wbxml2 Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release Not in release Not in release
vnc4 Not in release Not in release Not in release Not in release Vulnerable
cableswig Not in release Not in release Not in release Not in release Not in release
expat Not affected Not affected Not affected Not affected Fixed
gdcm Not affected Not affected Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
thunderbird Fixed Fixed Fixed Fixed Fixed
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
Show all 32 packages Show less packages

CVE-2019-14817

Medium priority
Fixed

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-14813

Medium priority
Fixed

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-14812

Medium priority
Fixed

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-14811

Medium priority
Fixed

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2019-10216

Medium priority
Fixed

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted...

1 affected package

ghostscript

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages