Search CVE reports


Toggle filters

51 – 60 of 140 results


CVE-2017-16942

Negligible priority

Some fixes available 2 of 3

In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Not affected
Show less packages

CVE-2017-13815

Medium priority
Ignored

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "file" product. Versions before 5.31 allow remote attackers to cause a denial of service (application crash)...

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2017-14634

Negligible priority

Some fixes available 4 of 6

In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed
Show less packages

CVE-2017-14246

Low priority

Some fixes available 4 of 6

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed
Show less packages

CVE-2017-14245

Low priority

Some fixes available 4 of 6

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed
Show less packages

CVE-2017-1000249

Medium priority
Fixed

An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in...

1 affected package

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2017-12562

Low priority

Some fixes available 2 of 3

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Not affected
Show less packages

CVE-2017-6892

Low priority

Some fixes available 2 of 4

In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Not affected
Show less packages

CVE-2017-8365

Low priority

Some fixes available 4 of 5

The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile
Show less packages

CVE-2017-8363

Low priority

Some fixes available 4 of 5

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

1 affected package

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile
Show less packages