Search CVE reports
131 – 140 of 187 results
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered...
7 affected packages
xpdf, poppler, libextractor, ipe, emscripten...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xpdf | Not affected | Not affected | Not in release | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected |
libextractor | Not affected | Not affected | Not affected | Not affected |
ipe | Not affected | Not affected | Not affected | Not affected |
emscripten | Ignored | Ignored | Not in release | Ignored |
utopia-documents | Not in release | Not in release | Not in release | Not in release |
texlive-bin | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an...
7 affected packages
xpdf, poppler, libextractor, ipe, texlive-bin...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xpdf | Not affected | Not affected | Not in release | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected |
libextractor | Not affected | Not affected | Not affected | Not affected |
ipe | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
utopia-documents | Not in release | Not in release | Not in release | Not in release |
emscripten | Ignored | Ignored | Not in release | Ignored |
Some fixes available 25 of 121
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...
32 affected packages
coin3, vnc4, xmlrpc-c, libxmltok, audacity...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Vulnerable |
vnc4 | Not in release | Not in release | Not in release | Vulnerable |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Fixed | Fixed | Fixed | Fixed |
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
poco | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kompozer | Not in release | Not in release | Not in release | Not in release |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
simgear | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Not affected | Not affected | Not in release | Not affected |
thunderbird | Not affected | Not affected | Not in release | Not affected |
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded...
1 affected package
texlive-bin
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
texlive-bin | — | — | — | Fixed |
Some fixes available 7 of 99
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
33 affected packages
audacity, matanza, cadaver, cmake, firefox...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
cadaver | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
firefox | Not affected | Not affected | Not in release | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
tdom | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
thunderbird | Not affected | Not affected | Not in release | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
expat | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
vnc4 | Not in release | Not in release | Not in release | Ignored |
poco | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 8 of 9
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.
3 affected packages
luatex, poppler, texlive-bin
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
luatex | — | — | — | Not in release |
poppler | — | — | — | Fixed |
texlive-bin | — | — | — | Not affected |
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to...
3 affected packages
texlive-base, context, texlive-bin
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
texlive-base | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
context | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
texlive-bin | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 5 of 99
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this...
31 affected packages
xmlrpc-c, audacity, ayttm, cableswig, cmake...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
audacity | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
matanza | Not affected | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
swish-e | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
xotcl | Not affected | Not affected | Not affected | Not affected |
expat | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
vnc4 | Not in release | Not in release | Not in release | Ignored |
poco | Not affected | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
cadaver | Not affected | Not affected | Not affected | Not affected |
gdcm | Not affected | Not affected | Not affected | Not affected |
coin3 | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 2 of 6
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
2 affected packages
texlive-base, texlive-bin
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
texlive-base | — | — | — | — |
texlive-bin | — | — | — | — |
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
1 affected package
texlive-bin
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
texlive-bin | — | — | — | — |