Search CVE reports


Toggle filters

221 – 230 of 465 results


CVE-2018-12356

Medium priority
Vulnerable

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers...

1 affected package

password-store

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
password-store Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10539

Medium priority

Some fixes available 15 of 17

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular...

1 affected package

node-negotiator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-negotiator Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-11093

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.

1 affected package

ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected
Show less packages

CVE-2018-11033

Negligible priority
Vulnerable

The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-10361

Medium priority
Vulnerable

An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on...

1 affected package

ktexteditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ktexteditor Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-9861

Medium priority

Some fixes available 2 of 8

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows...

1 affected package

ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Fixed
Show less packages

CVE-2018-8107

Negligible priority
Vulnerable

The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

4 affected packages

libextractor, ipe, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-8106

Negligible priority
Vulnerable

The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-8105

Negligible priority
Vulnerable

The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

4 affected packages

libextractor, ipe, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libextractor Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
poppler Not affected Not affected Not affected Not affected
xpdf Vulnerable Vulnerable Not in release Vulnerable
Show less packages

CVE-2018-8104

Negligible priority
Vulnerable

The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

4 affected packages

xpdf, libextractor, ipe, poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Not in release Vulnerable
libextractor Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
poppler Not affected Not affected Not affected Not affected
Show less packages