Search CVE reports


Toggle filters

41241 – 41250 of 69301 results


CVE-2018-19212

Low priority
Needs evaluation

In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.

5 affected packages

android, chromium-browser, sludge, libvpx, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release Not in release Not in release
chromium-browser Not affected Not affected Not affected Not in release Not affected
sludge Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libvpx Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-19211

Low priority
Fixed

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*'...

1 affected package

ncurses

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ncurses Not affected Not affected Fixed
Show less packages

CVE-2018-19209

Negligible priority
Vulnerable

Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.

1 affected package

nasm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19208

Low priority
Vulnerable

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

1 affected package

libwpd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libwpd Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19206

Medium priority

Some fixes available 2 of 3

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

1 affected package

roundcube

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-19205

Medium priority

Some fixes available 2 of 3

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated...

1 affected package

roundcube

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-19200

Medium priority

Some fixes available 4 of 5

An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

1 affected package

uriparser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
uriparser Not affected Not affected Fixed
Show less packages

CVE-2018-19199

Medium priority

Some fixes available 4 of 5

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

1 affected package

uriparser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
uriparser Not affected Not affected Fixed
Show less packages

CVE-2018-19198

Medium priority

Some fixes available 4 of 5

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

1 affected package

uriparser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
uriparser Not affected Not affected Fixed
Show less packages

CVE-2018-19210

Low priority
Fixed

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

1 affected package

tiff

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Fixed
Show less packages