Search CVE reports


Toggle filters

191 – 200 of 465 results


CVE-2019-9587

Negligible priority
Vulnerable

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, ipe, libextractor, poppler, utopia-documents, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
ipe Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-8955

Medium priority

Some fixes available 1 of 2

In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor Not affected Not affected Fixed
Show less packages

CVE-2019-7560

Medium priority
Not affected

In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_assumptions or btor_delete.

1 affected package

boolector

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
boolector Not affected
Show less packages

CVE-2019-2435

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 8.0.13 and prior and 2.1.8 and prior. Easily exploitable vulnerability allows...

1 affected package

mysql-connector-python

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-python Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-20431

Medium priority

Some fixes available 2 of 4

GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-20430

Medium priority

Some fixes available 2 of 4

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-15537

Medium priority
Vulnerable

Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-17960

Medium priority
Needs evaluation

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

2 affected packages

ckeditor, fckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Not affected Needs evaluation
fckeditor Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-18651

Low priority
Needs evaluation

An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by...

4 affected packages

ipe, libextractor, xpdf, poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18650

Medium priority
Needs evaluation

An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused...

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
Show less packages