Search CVE reports


Toggle filters

11 – 20 of 139 results


CVE-2022-29620

Negligible priority
Not affected

FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability

1 affected package

filezilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
filezilla Not affected Not affected Not affected
Show less packages

CVE-2022-24599

Low priority

Some fixes available 7 of 9

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the...

1 affected package

audiofile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Fixed Fixed Fixed
Show less packages

CVE-2021-43820

Medium priority
Not affected

Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a...

1 affected package

seafile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seafile Not affected Not affected Not affected
Show less packages

CVE-2021-4156

Low priority

Some fixes available 5 of 9

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and...

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-3246

Medium priority

Some fixes available 7 of 8

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Fixed Fixed Fixed
Show less packages

CVE-2021-30146

Medium priority
Needs evaluation

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

1 affected package

seafile-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seafile-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-36314

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain...

1 affected package

file-roller

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2020-18781

Medium priority
Not affected

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

1 affected package

audiofile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Not affected Not affected Not affected
Show less packages

CVE-2020-11736

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

1 affected package

file-roller

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2019-8907

Medium priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Fixed
Show less packages