Search CVE reports
1 – 10 of 36272 results
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in...
2 affected packages
kf5-messagelib, messagelib
| Package | 20.04 LTS |
|---|---|
| kf5-messagelib | Needs evaluation |
| messagelib | — |
libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes...
1 affected package
libsodium
| Package | 20.04 LTS |
|---|---|
| libsodium | Needs evaluation |
coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't...
1 affected package
coturn
| Package | 20.04 LTS |
|---|---|
| coturn | Needs evaluation |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow....
1 affected package
imagemagick
| Package | 20.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
[Unknown description]
1 affected package
wget2
| Package | 20.04 LTS |
|---|---|
| wget2 | Needs evaluation |
[Unknown description]
1 affected package
wget2
| Package | 20.04 LTS |
|---|---|
| wget2 | Needs evaluation |
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
1 affected package
gnupg2
| Package | 20.04 LTS |
|---|---|
| gnupg2 | Needs evaluation |
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the...
1 affected package
gnupg2
| Package | 20.04 LTS |
|---|---|
| gnupg2 | Needs evaluation |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS...
1 affected package
imagemagick
| Package | 20.04 LTS |
|---|---|
| imagemagick | Needs evaluation |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
1 affected package
imagemagick
| Package | 20.04 LTS |
|---|---|
| imagemagick | Needs evaluation |