Search CVE reports
51 – 60 of 243 results
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Fixed | Fixed | Not affected |
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If...
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Fixed | Fixed | Fixed |
Some fixes available 11 of 94
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
24 affected packages
xmlrpc-c, cableswig, apache2, apr-util, cmake...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
cableswig | — | Not in release | Not in release | Not in release |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
ghostscript | Not affected | Not affected | Not affected | Not affected |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
vnc4 | — | Not in release | Not in release | Needs evaluation |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ayttm | — | Not in release | Not in release | Not in release |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
firefox | Not affected | Not affected | Not in release | Ignored |
gdcm | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | — | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
libxmltok | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
smart | — | Not in release | Not in release | Not affected |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
thunderbird | Ignored | Ignored | Not in release | Ignored |
vtk | — | Not in release | Not in release | Not in release |
Some fixes available 13 of 118
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
24 affected packages
firefox, cadaver, coin3, gdcm, libxmltok...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Fixed |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
coin3 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
thunderbird | Ignored | Ignored | Not in release | Ignored |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
vnc4 | — | Not in release | Not in release | Needs evaluation |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
ayttm | — | Not in release | Not in release | Not in release |
cableswig | — | Not in release | Not in release | Not in release |
smart | — | Not in release | Not in release | Needs evaluation |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | — | Not in release | Not in release | Not in release |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
vtk | — | Not in release | Not in release | Not in release |
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer...
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Not affected | Fixed | Fixed |
Some fixes available 1 of 2
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device...
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Fixed | Not affected | Not affected |
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Not affected | Not affected | Fixed |
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The...
1 affected package
ghostscript
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Not affected | Not affected | Not affected |
Some fixes available 4 of 46
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls...
7 affected packages
insighttoolkit4, openjpeg2, ghostscript, blender, openjpeg...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
openjpeg2 | Not affected | Fixed | Fixed | Fixed |
ghostscript | Not affected | Not affected | Not affected | Not affected |
blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
openjpeg | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 7 of 60
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled...
7 affected packages
openjpeg2, blender, ghostscript, insighttoolkit4, openjpeg...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg2 | Fixed | Fixed | Fixed | Fixed |
blender | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
openjpeg | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
texmaker | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |