Search CVE reports


Toggle filters

31 – 40 of 44 results


CVE-2020-27824

Medium priority

Some fixes available 18 of 69

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this...

7 affected packages

openjpeg2, texmaker, blender, insighttoolkit4, qtwebengine-opensource-src...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Fixed Fixed Fixed Fixed Fixed
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Fixed
openjpeg Not in release Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2020-27823

Medium priority

Some fixes available 15 of 65

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as...

7 affected packages

texmaker, blender, insighttoolkit4, qtwebengine-opensource-src, ghostscript...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Not affected
openjpeg2 Fixed Fixed Fixed Fixed Fixed
openjpeg Not in release Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2020-27814

Medium priority

Some fixes available 17 of 30

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running...

7 affected packages

blender, ghostscript, insighttoolkit4, openjpeg, openjpeg2...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
blender Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Fixed
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
texmaker Not affected Not affected Not affected Not affected Not affected
qtwebengine-opensource-src Vulnerable Vulnerable Vulnerable Vulnerable Not affected
Show all 7 packages Show less packages

CVE-2020-15999

High priority
Fixed

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

chromium-browser, godot, graphicsmagick, musescore, openjdk-13...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Fixed
godot Not affected Not affected Not affected Not in release
graphicsmagick Not affected Not affected Not affected Not affected
musescore Not in release Not in release Not affected Not affected
openjdk-13 Not in release Not in release Not affected Not in release
texmaker Not affected Not affected Not affected Not affected
android Not in release Not in release Not in release Not in release
firefox Not affected Not affected Not in release Not affected
freetype Fixed Fixed Fixed Fixed
openjdk-lts Not affected Not affected Not affected Not affected
openjdk-15 Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
paraview Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
openjdk-12 Not in release Not in release Not in release Not in release
qtbase-opensource-src-gles Not affected Not affected Not affected Not in release
texlive-bin Not affected Not affected Not affected Not affected
Show all 18 packages Show less packages

CVE-2020-8112

Medium priority

Some fixes available 17 of 72

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

7 affected packages

ghostscript, openjpeg, openjpeg2, blender, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Not affected Not affected Not affected Fixed
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2020-6851

Medium priority

Some fixes available 17 of 77

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

7 affected packages

texmaker, blender, ghostscript, insighttoolkit4, openjpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Fixed
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2019-17546

Medium priority

Some fixes available 5 of 66

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param"...

17 affected packages

blender, chromium-browser, ivtools, xloadimage, neuron...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
blender Not affected Not affected Not affected Not affected Not affected
chromium-browser Not affected Not affected Not affected Not in release Not affected
ivtools Not affected Not affected Not affected Not affected Not affected
xloadimage Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
openjpeg2 Not affected Not affected Not affected Not affected Not affected
qt4-x11 Not in release Not in release Not in release Not in release Not affected
tiff Not affected Not affected Not affected Not affected Fixed
qtimageformats-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
gdal Not affected Not affected Not affected Not affected Not affected
libtk-img Not affected Not affected Not affected Not affected Not affected
paraview Needs evaluation Not affected Not affected Not affected Not affected
povray Not affected Not affected Not affected Not affected Not affected
sfftobmp Not in release Not affected Not affected Not affected Not affected
Show all 17 packages Show less packages

CVE-2019-16707

Low priority
Needs evaluation

Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.

10 affected packages

calibre, chromium, texmaker, enchant, firefox...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
calibre Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium Not in release Not in release Not in release Not in release Not in release
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
enchant Not in release Not in release Not in release Needs evaluation Needs evaluation
firefox Not affected Not affected Not affected Not in release Not affected
postbooks Not in release Not in release Not in release Not in release Needs evaluation
thunderbird Not affected Not affected Not affected Not in release Not affected
focuswriter Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
hunspell Not affected Not affected Not affected Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 10 packages Show less packages

CVE-2018-21010

Medium priority

Some fixes available 2 of 62

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

8 affected packages

qtwebengine-opensource-src, blender, gdcm, ghostscript, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected Fixed
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2019-12973

Low priority

Some fixes available 15 of 97

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to...

9 affected packages

blender, emscripten, gdcm, ghostscript, insighttoolkit4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emscripten Ignored Ignored Ignored Not in release Ignored
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
openjpeg Not in release Not in release Not in release Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 9 packages Show less packages