Search CVE reports


Toggle filters

131 – 140 of 187 results


CVE-2019-12493

Negligible priority
Vulnerable

A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered...

7 affected packages

xpdf, poppler, libextractor, ipe, emscripten...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
ipe Not affected Not affected Not affected Not affected
emscripten Ignored Ignored Not in release Ignored
utopia-documents Not in release Not in release Not in release Not in release
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
Show all 7 packages Show less packages

CVE-2019-12360

Low priority
Vulnerable

A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an...

7 affected packages

xpdf, poppler, libextractor, ipe, texlive-bin...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
ipe Not affected Not affected Not affected Not affected
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
utopia-documents Not in release Not in release Not in release Not in release
emscripten Ignored Ignored Not in release Ignored
Show all 7 packages Show less packages

CVE-2018-20843

Low priority

Some fixes available 25 of 121

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...

32 affected packages

coin3, vnc4, xmlrpc-c, libxmltok, audacity...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coin3 Not affected Not affected Not affected Vulnerable
vnc4 Not in release Not in release Not in release Vulnerable
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Fixed Fixed Fixed Fixed
audacity Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
expat Fixed Fixed Fixed Fixed
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
wxwidgets2.8 Not in release Not in release Not in release Not in release
wxwidgets2.6 Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
libparagui1.1 Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kompozer Not in release Not in release Not in release Not in release
insighttoolkit Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
simgear Not affected Not affected Not affected Not affected
tdom Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release Not in release
smart Not in release Not in release Not in release Not affected
firefox Not affected Not affected Not in release Not affected
thunderbird Not affected Not affected Not in release Not affected
Show all 32 packages Show less packages

CVE-2018-17407

Medium priority
Fixed

An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded...

1 affected package

texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Fixed
Show less packages

CVE-2017-9233

Medium priority

Some fixes available 7 of 99

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

33 affected packages

audacity, matanza, cadaver, cmake, firefox...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audacity Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
cadaver Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
firefox Not affected Not affected Not in release Not affected
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
tla Not affected Not affected Not affected Not affected
wbxml2 Not affected Not affected Not affected Not affected
wxwidgets2.8 Not in release Not in release Not in release Not in release
expat Not affected Not affected Not affected Not affected
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
xmlrpc-c Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release
vnc4 Not in release Not in release Not in release Ignored
poco Not affected Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
libparagui1.1 Not in release Not in release Not in release Not in release
kompozer Not in release Not in release Not in release Not in release
gdcm Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
coin3 Not affected Not affected Not affected Needs evaluation
vtk Not in release Not in release Not in release Not in release
libxmltok Not affected Not affected Not affected Not affected
Show all 33 packages Show less packages

CVE-2017-9083

Low priority

Some fixes available 8 of 9

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

3 affected packages

luatex, poppler, texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luatex Not in release
poppler Fixed
texlive-bin Not affected
Show less packages

CVE-2017-17513

Negligible priority
Vulnerable

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to...

3 affected packages

texlive-base, context, texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-base Vulnerable Vulnerable Vulnerable Vulnerable
context Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texlive-bin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2016-5300

Medium priority

Some fixes available 5 of 99

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this...

31 affected packages

xmlrpc-c, audacity, ayttm, cableswig, cmake...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable
audacity Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
cmake Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
matanza Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
smart Not in release Not in release Not in release Not affected
swish-e Not affected Not affected Not affected Not affected
tdom Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
tla Not affected Not affected Not affected Not affected
wbxml2 Not affected Not affected Not affected Not affected
wxwidgets2.8 Not in release Not in release Not in release Not in release
xotcl Not affected Not affected Not affected Not affected
expat Not affected Not affected Not affected Not affected
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release
vnc4 Not in release Not in release Not in release Ignored
poco Not affected Not affected Not affected Not affected
libparagui1.1 Not in release Not in release Not in release Not in release
kompozer Not in release Not in release Not in release Not in release
cadaver Not affected Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release Not in release
libxmltok Not affected Not affected Not affected Not affected
Show all 31 packages Show less packages

CVE-2016-10243

Medium priority

Some fixes available 2 of 6

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

2 affected packages

texlive-base, texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-base
texlive-bin
Show less packages

CVE-2015-5701

Medium priority
Not affected

mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.

1 affected package

texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin
Show less packages