Search CVE reports
361 – 370 of 41351 results
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize...
1 affected package
python-keystonemiddleware
| Package | 18.04 LTS |
|---|---|
| python-keystonemiddleware | Not affected |
Some fixes available 1 of 2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 18.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | Fixed |
| freerdp3 | — |
Some fixes available 1 of 2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 18.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | Fixed |
| freerdp3 | — |
Some fixes available 1 of 2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 18.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | Fixed |
| freerdp3 | — |
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the...
1 affected package
assimp
| Package | 18.04 LTS |
|---|---|
| assimp | Needs evaluation |
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow....
1 affected package
mapnik
| Package | 18.04 LTS |
|---|---|
| mapnik | Needs evaluation |
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The...
1 affected package
opencc
| Package | 18.04 LTS |
|---|---|
| opencc | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 18.04 LTS |
|---|---|
| gradle | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 18.04 LTS |
|---|---|
| gradle | Needs evaluation |
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...
1 affected package
node-tar
| Package | 18.04 LTS |
|---|---|
| node-tar | Needs evaluation |