Search CVE reports
21 – 30 of 248 results
Some fixes available 10 of 37
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
7 affected packages
openjpeg2, insighttoolkit4, qtwebengine-opensource-src, blender, texmaker...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| openjpeg2 | Fixed | Fixed | Fixed | Fixed | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| ghostscript | Not affected | Not affected | Not affected | Fixed | 
| openjpeg | Not in release | Not in release | Not in release | — | 
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Fixed | Fixed | Fixed | 
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Fixed | Fixed | Fixed | 
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Not affected | Not affected | Not affected | 
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and...
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Fixed | Fixed | Fixed | 
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Fixed | Not affected | Not affected | 
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
1 affected package
ghostscript
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Fixed | Fixed | Fixed | Fixed | 
Some fixes available 7 of 74
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
23 affected packages
smart, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| expat | Fixed | Fixed | Fixed | Fixed | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Not affected | Not affected | Not affected | Not affected | 
Some fixes available 6 of 73
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
tdom, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Not affected | Not affected | Not affected | Not affected | 
| expat | Fixed | Fixed | Fixed | Fixed | 
Some fixes available 13 of 80
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Fixed | Fixed | Fixed | Fixed | 
| expat | Fixed | Fixed | Fixed | Fixed |