Search CVE reports


Toggle filters

1 – 10 of 195 results


CVE-2025-43964

Medium priority

Some fixes available 7 of 51

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

8 affected packages

dcraw, ufraw, darktable, exactimage, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2025-43963

Medium priority

Some fixes available 7 of 51

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2025-43962

Medium priority

Some fixes available 7 of 51

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2025-43961

Medium priority

Some fixes available 7 of 51

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

8 affected packages

dcraw, ufraw, darktable, exactimage, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2023-30207

Medium priority
Needs evaluation

A divide by zero issue discovered in Kodi Home Theater Software 19.5 and earlier allows attackers to cause a denial of service via use of crafted mp3 file.

1 affected package

kodi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-23082

Medium priority
Needs evaluation

A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.

1 affected package

kodi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-1729

Medium priority

Some fixes available 11 of 68

A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

9 affected packages

libraw, ufraw, darktable, exactimage, dcraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Fixed Fixed Fixed Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xbmc Not in release Not in release Not in release Not in release
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Fixed Fixed Fixed
Show all 9 packages Show less packages

CVE-2022-43038

Medium priority
Needs evaluation

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

1 affected package

kodi-inputstream-adaptive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi-inputstream-adaptive Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-43037

Medium priority
Needs evaluation

An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.

1 affected package

kodi-inputstream-adaptive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi-inputstream-adaptive Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-43035

Medium priority
Needs evaluation

An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

1 affected package

kodi-inputstream-adaptive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi-inputstream-adaptive Needs evaluation Needs evaluation Not in release Not in release
Show less packages