Search CVE reports


Toggle filters

131 – 140 of 243 results


CVE-2018-21010

Medium priority

Some fixes available 2 of 61

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

8 affected packages

qtwebengine-opensource-src, blender, gdcm, ghostscript, insighttoolkit4...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Needs evaluation Needs evaluation Needs evaluation
openjpeg Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Fixed
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2018-20843

Low priority

Some fixes available 25 of 121

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...

32 affected packages

apache2, ghostscript, libparagui1.1, poco, sitecopy...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
libparagui1.1 Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
audacity Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
coin3 Not affected Not affected Not affected Vulnerable
firefox Not affected Not affected Not in release Not affected
matanza Ignored Ignored Ignored Ignored
smart Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
vtk Not in release Not in release Not in release Not in release
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wxwidgets2.8 Not in release Not in release Not in release Not in release
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Fixed Fixed Fixed Fixed
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed
gdcm Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release
simgear Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Vulnerable
wbxml2 Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release
Show all 32 packages Show less packages

CVE-2018-19478

Medium priority
Fixed

In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-19477

Medium priority
Fixed

psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-19476

Medium priority
Fixed

psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-19475

Medium priority
Fixed

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-19409

Medium priority
Fixed

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-19134

Medium priority
Fixed

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the...

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-18284

Medium priority
Fixed

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages

CVE-2018-18073

Medium priority
Fixed

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed
Show less packages