Search CVE reports


Toggle filters

41871 – 41880 of 69503 results


CVE-2018-17100

Medium priority
Fixed

An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.

1 affected package

tiff

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed
Show less packages

CVE-2018-17095

Medium priority

Some fixes available 3 of 5

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

1 affected package

audiofile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Not affected Not affected Fixed
Show less packages

CVE-2018-12086

Medium priority
Not affected

Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected
Show less packages

CVE-2018-17057

Medium priority
Vulnerable

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

1 affected package

tcpdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tcpdf Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-14638

Medium priority
Vulnerable

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.

1 affected package

389-ds-base

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
389-ds-base Needs evaluation Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-17019

Medium priority
Needs evaluation

In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.

1 affected package

bro

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bro Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-16999

Low priority
Vulnerable

Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.

1 affected package

nasm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-16745

Low priority
Needs evaluation

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow a buffer overflow if long untrusted input can reach it.

1 affected package

mgetty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mgetty Not affected Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-16744

Low priority
Needs evaluation

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input can reach it, because popen is used.

1 affected package

mgetty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mgetty Not affected Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-16743

Low priority
Needs evaluation

An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based buffer overflow.

1 affected package

mgetty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mgetty Not affected Not affected Not affected Not affected Needs evaluation
Show less packages