Search CVE reports
21 – 30 of 79 results
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of CVE-2016-3182. Notes: All CVE users should reference CVE-2016-3182 instead of this candidate. All references...
1 affected package
openjpeg2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| openjpeg2 | — | — | — | — | 
Some fixes available 16 of 71
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
7 affected packages
ghostscript, openjpeg, openjpeg2, blender, insighttoolkit4...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| ghostscript | Not affected | Not affected | Not affected | Fixed | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
| openjpeg2 | Fixed | Fixed | Fixed | Fixed | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
Some fixes available 16 of 76
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
7 affected packages
texmaker, blender, ghostscript, insighttoolkit4, openjpeg...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| ghostscript | Not affected | Not affected | Not affected | Fixed | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
| openjpeg2 | Fixed | Fixed | Fixed | Fixed | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
Some fixes available 5 of 64
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param"...
17 affected packages
blender, chromium-browser, ivtools, xloadimage, neuron...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| blender | Not affected | Not affected | Not affected | Not affected | 
| chromium-browser | Not affected | Not affected | Not in release | Not affected | 
| ivtools | Not affected | Not affected | Not affected | Not affected | 
| xloadimage | Not affected | Not affected | Not affected | Not affected | 
| neuron | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | 
| openjpeg2 | Not affected | Not affected | Not affected | Not affected | 
| qt4-x11 | Not in release | Not in release | Not in release | Not affected | 
| tiff | Not affected | Not affected | Not affected | Fixed | 
| qtimageformats-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Not affected | Not affected | Not affected | 
| gdal | Not affected | Not affected | Not affected | Not affected | 
| libtk-img | Not affected | Not affected | Not affected | Not affected | 
| paraview | Not affected | Not affected | Not affected | Not affected | 
| povray | Not affected | Not affected | Not affected | Not affected | 
| sfftobmp | Not affected | Not affected | Not affected | Not affected | 
Some fixes available 2 of 64
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
8 affected packages
qtwebengine-opensource-src, blender, gdcm, ghostscript, insighttoolkit4...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
| openjpeg2 | Not affected | Not affected | Not affected | Fixed | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
Some fixes available 14 of 95
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to...
9 affected packages
blender, emscripten, gdcm, ghostscript, insighttoolkit4...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| emscripten | Ignored | Ignored | Not in release | Ignored | 
| gdcm | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
| openjpeg2 | Fixed | Fixed | Fixed | Fixed | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
Some fixes available 1 of 80
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
8 affected packages
texmaker, blender, insighttoolkit4, qtwebengine-opensource-src, emscripten...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| emscripten | Ignored | Ignored | Not in release | Ignored | 
| gdcm | Not affected | Not affected | Not affected | Not affected | 
| openjpeg2 | Not affected | Not affected | Not affected | Not affected | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service...
8 affected packages
blender, emscripten, insighttoolkit4, qtwebengine-opensource-src, texmaker...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| emscripten | Ignored | Ignored | Not in release | Ignored | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Not affected | 
| openjpeg2 | Not affected | Not affected | Not affected | Not affected | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
Some fixes available 1 of 88
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
8 affected packages
emscripten, qtwebengine-opensource-src, texmaker, blender, insighttoolkit4...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| emscripten | Ignored | Ignored | Not in release | Ignored | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| openjpeg | Not in release | Not in release | Not in release | Not in release | 
| gdcm | Not affected | Not affected | Not affected | Not affected | 
| openjpeg2 | Not affected | Not affected | Not affected | Fixed | 
Some fixes available 4 of 58
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this...
9 affected packages
chromium, texmaker, qtimageformats-opensource-src, qtwebengine-opensource-src, gdal...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| chromium | Not in release | Not in release | Not in release | Not in release | 
| texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtimageformats-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdal | Not affected | Not affected | Not affected | Not affected | 
| qt4-x11 | Not in release | Not in release | Not in release | Not affected | 
| tiff | Not affected | Not affected | Not affected | Fixed | 
| tiff3 | Not in release | Not in release | Not in release | Not in release | 
| openjpeg2 | Not affected | Not affected | Not affected | Not affected |