Search CVE reports


Toggle filters

211 – 220 of 465 results


CVE-2018-16369

Negligible priority
Vulnerable

XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.

4 affected packages

poppler, ipe, libextractor, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-16368

Negligible priority
Vulnerable

SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-14857

Medium priority
Not affected

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected
Show less packages

CVE-2018-14473

Medium priority
Vulnerable

OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-12483

Medium priority
Vulnerable

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-12482

Medium priority
Vulnerable

OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14347

Medium priority

Some fixes available 2 of 5

GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14346

Medium priority

Some fixes available 2 of 5

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

1 affected package

libextractor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1000558

Negligible priority
Needs evaluation

OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-1000557

Negligible priority
Needs evaluation

OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) code within...

1 affected package

ocsinventory-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected Not affected Not affected Needs evaluation
Show less packages