Search CVE reports


Toggle filters

21 – 30 of 139 results


CVE-2019-8906

Medium priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Fixed
Show less packages

CVE-2019-8905

Low priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Fixed
Show less packages

CVE-2019-8904

Low priority
Fixed

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Not affected
Show less packages

CVE-2019-5429

Low priority
Vulnerable

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

1 affected package

filezilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
filezilla Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-3832

Low priority
Fixed

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed
Show less packages

CVE-2019-18218

Medium priority
Fixed

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Fixed
Show less packages

CVE-2019-16680

Medium priority
Fixed

An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

1 affected package

file-roller

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed
Show less packages

CVE-2019-13147

Medium priority

Some fixes available 7 of 17

In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

1 affected package

audiofile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Vulnerable Fixed Fixed Fixed
Show less packages

CVE-2018-9206

High priority
Fixed

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

1 affected package

libjs-jquery-file-upload

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjs-jquery-file-upload Fixed
Show less packages

CVE-2018-6557

Low priority
Fixed

The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial...

1 affected package

base-files

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
base-files Fixed
Show less packages