Search CVE reports


Toggle filters

161 – 170 of 366 results


CVE-2018-10529

Medium priority

Some fixes available 19 of 102

An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp.

8 affected packages

libraw, ufraw, xbmc, darktable, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Fixed Fixed Fixed Fixed Fixed
ufraw Not in release Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2018-10528

Medium priority

Some fixes available 19 of 102

An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.

8 affected packages

kodi, rawtherapee, xbmc, libraw, ufraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
libraw Fixed Fixed Fixed Fixed Fixed
ufraw Not in release Not in release Not in release Not in release Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2018-8831

Medium priority
Needs evaluation

A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.

2 affected packages

kodi, xbmc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0493

Medium priority

Some fixes available 18 of 19

remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.

1 affected package

remctl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
remctl Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-1000127

Medium priority
Fixed

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack...

1 affected package

memcached

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
memcached
Show less packages

CVE-2018-1323

Medium priority
Not affected

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the...

1 affected package

tomcat8

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8
Show less packages

CVE-2018-5802

Medium priority

Some fixes available 3 of 86

An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

8 affected packages

libraw, ufraw, xbmc, darktable, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2018-5801

Medium priority

Some fixes available 3 of 86

An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference.

8 affected packages

kodi, xbmc, libraw, ufraw, darktable...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Ignored
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2018-5800

Medium priority

Some fixes available 3 of 86

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

8 affected packages

dcraw, exactimage, darktable, libraw, ufraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release Not in release
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2018-1000115

Low priority
Fixed

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network...

1 affected package

memcached

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
memcached
Show less packages