Search CVE reports


Toggle filters

651 – 660 of 2921 results


CVE-2022-3266

Medium priority
Fixed

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Fixed Fixed
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-40674

Medium priority

Some fixes available 14 of 127

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

24 affected packages

firefox, cadaver, coin3, gdcm, libxmltok...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Fixed Fixed
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
coin3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libxmltok Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
thunderbird Ignored Ignored Not in release Ignored
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed
vnc4 Not in release Not in release Needs evaluation
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release
cableswig Not in release Not in release Not in release
smart Not in release Not in release Needs evaluation
ghostscript Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release
Show all 24 packages Show less packages

CVE-2022-38476

Medium priority

Some fixes available 3 of 4

A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability...

2 affected packages

firefox-esr, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-esr Not in release Not in release Not in release
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2021-4214

Medium priority
Not affected

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a...

5 affected packages

thunderbird, chromium-browser, firefox, libpng, libpng1.6

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Not in release Not affected
chromium-browser Not affected Not in release Not affected
firefox Not affected Not in release Not affected
libpng Not in release Not in release Not in release
libpng1.6 Not affected Not affected Not affected
Show less packages

CVE-2022-38478

Medium priority

Some fixes available 5 of 14

Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of...

7 affected packages

mozjs78, firefox, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs78 Not in release Ignored Not in release Not in release
firefox Not affected Not affected Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs91 Not in release Ignored Not in release Not in release
thunderbird Not affected Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-38477

Medium priority

Some fixes available 5 of 14

Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort...

7 affected packages

mozjs78, thunderbird, firefox, mozjs38, mozjs52...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs78 Not in release Ignored Not in release Not in release
thunderbird Not affected Fixed Fixed Fixed
firefox Not affected Not affected Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs91 Not in release Ignored Not in release Not in release
Show all 7 packages Show less packages

CVE-2022-38475

Medium priority

Some fixes available 4 of 13

An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.

7 affected packages

thunderbird, mozjs38, mozjs52, mozjs68, mozjs78...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Fixed Fixed Ignored
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs78 Not in release Ignored Not in release Not in release
mozjs91 Not in release Ignored Not in release Not in release
firefox Not affected Not affected Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-38473

Medium priority

Some fixes available 5 of 6

A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13,...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Fixed Fixed
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-38472

Medium priority

Some fixes available 5 of 6

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Fixed Fixed
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-2505

Medium priority

Some fixes available 5 of 14

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs78 Not in release Ignored Not in release Not in release
mozjs91 Not in release Ignored Not in release Not in release
thunderbird Not affected Fixed Fixed Fixed
Show all 7 packages Show less packages