Search CVE reports


Toggle filters

1 – 10 of 44 results


CVE-2026-6192

Medium priority

Some fixes available 4 of 35

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out...

7 affected packages

openjpeg2, insighttoolkit4, qtwebengine-opensource-src, blender, texmaker...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Fixed Fixed Fixed Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Needs evaluation
openjpeg Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2026-4775

Medium priority
Needs evaluation

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61145

Low priority

Some fixes available 9 of 25

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61144

Low priority

Some fixes available 7 of 24

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Vulnerable Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61143

Low priority

Some fixes available 7 of 24

libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Vulnerable Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-9900

High priority

Some fixes available 9 of 24

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
texmaker Not affected Vulnerable Vulnerable Vulnerable Vulnerable
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-9165

Low priority

Some fixes available 9 of 29

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak....

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8961

Low priority
Fixed

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The...

5 affected packages

qtwebengine-opensource-src, texmaker, gdal, neuron, tiff

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Not affected Not affected Not affected Not affected
texmaker Not affected Not affected Not affected Not affected
gdal Not affected Not affected Not affected Not affected
neuron Not affected Not affected Not affected Not affected
tiff Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-8851

Medium priority

Some fixes available 7 of 27

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Fixed Fixed Fixed Fixed
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdal Not affected Not affected Not affected Not affected Not affected
neuron Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-50952

Medium priority

Some fixes available 4 of 35

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

7 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, ghostscript...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Needs evaluation
openjpeg Not in release Not in release Not in release
openjpeg2 Not affected Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages