Search CVE reports
1 – 10 of 36927 results
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the...
1 affected package
vim
| Package | 20.04 LTS |
|---|---|
| vim | Needs evaluation |
(@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ...)
1 affected package
node-brace-expansion
| Package | 20.04 LTS |
|---|---|
| node-brace-expansion | Needs evaluation |
[NULL dereference via C_DeriveKey with specific NULL parameters]
1 affected package
p11-kit
| Package | 20.04 LTS |
|---|---|
| p11-kit | Needs evaluation |
A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed...
1 affected package
mapnik
| Package | 20.04 LTS |
|---|---|
| mapnik | Needs evaluation |
Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the...
1 affected package
dnsmasq
| Package | 20.04 LTS |
|---|---|
| dnsmasq | Needs evaluation |
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom...
1 affected package
calibre
| Package | 20.04 LTS |
|---|---|
| calibre | Needs evaluation |
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The...
1 affected package
rust-time
| Package | 20.04 LTS |
|---|---|
| rust-time | Needs evaluation |
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion,...
1 affected package
calibre
| Package | 20.04 LTS |
|---|---|
| calibre | Needs evaluation |
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this...
1 affected package
calibre
| Package | 20.04 LTS |
|---|---|
| calibre | Needs evaluation |
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...
1 affected package
mupdf
| Package | 20.04 LTS |
|---|---|
| mupdf | Needs evaluation |