Search CVE reports
81 – 90 of 109 results
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
3 affected packages
qtwebengine-opensource-src, gst-libav1.0, ffmpeg
| Package | 24.04 LTS |
|---|---|
| qtwebengine-opensource-src | Needs evaluation |
| gst-libav1.0 | Needs evaluation |
| ffmpeg | Not affected |
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
8 affected packages
insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, gdcm...
| Package | 24.04 LTS |
|---|---|
| insighttoolkit4 | Not in release |
| qtwebengine-opensource-src | Needs evaluation |
| blender | Needs evaluation |
| texmaker | Needs evaluation |
| gdcm | Not affected |
| ghostscript | Not affected |
| openjpeg | Not in release |
| openjpeg2 | Not affected |
In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional...
2 affected packages
chromium-browser, qtwebengine-opensource-src
| Package | 24.04 LTS |
|---|---|
| chromium-browser | — |
| qtwebengine-opensource-src | — |
Some fixes available 1 of 2
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is...
7 affected packages
qtwebengine-opensource-src, godot, aom, chromium-browser, firefox...
| Package | 24.04 LTS |
|---|---|
| qtwebengine-opensource-src | Needs evaluation |
| godot | Fixed |
| aom | Not affected |
| chromium-browser | Not affected |
| firefox | Not affected |
| libvpx | Not affected |
| thunderbird | Not affected |
Some fixes available 1 of 5
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to...
9 affected packages
insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...
| Package | 24.04 LTS |
|---|---|
| insighttoolkit4 | Not in release |
| qtwebengine-opensource-src | Needs evaluation |
| blender | Needs evaluation |
| texmaker | Needs evaluation |
| emscripten | Ignored |
| gdcm | Not affected |
| ghostscript | Not affected |
| openjpeg | Not in release |
| openjpeg2 | Fixed |
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
8 affected packages
insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...
| Package | 24.04 LTS |
|---|---|
| insighttoolkit4 | Not in release |
| qtwebengine-opensource-src | Needs evaluation |
| blender | Needs evaluation |
| texmaker | Needs evaluation |
| emscripten | Ignored |
| gdcm | Not affected |
| openjpeg | Not in release |
| openjpeg2 | Not affected |
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service...
8 affected packages
insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...
| Package | 24.04 LTS |
|---|---|
| insighttoolkit4 | Not in release |
| qtwebengine-opensource-src | Needs evaluation |
| blender | Needs evaluation |
| texmaker | Needs evaluation |
| emscripten | Ignored |
| gdcm | Not affected |
| openjpeg | Not in release |
| openjpeg2 | Not affected |
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
8 affected packages
insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...
| Package | 24.04 LTS |
|---|---|
| insighttoolkit4 | Not in release |
| qtwebengine-opensource-src | Needs evaluation |
| blender | Needs evaluation |
| texmaker | Needs evaluation |
| emscripten | Ignored |
| gdcm | Not affected |
| openjpeg | Not in release |
| openjpeg2 | Not affected |
Some fixes available 2 of 4
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
5 affected packages
qtwebengine-opensource-src, sqlcipher, chromium, db5.3, sqlite3
| Package | 24.04 LTS |
|---|---|
| qtwebengine-opensource-src | Needs evaluation |
| sqlcipher | Vulnerable |
| chromium | Not in release |
| db5.3 | Fixed |
| sqlite3 | Fixed |
In libwebp 0.5.1, there is a double free bug in libwebpmux.
9 affected packages
firefox, godot, libwebp, mozjs38, mozjs52...
| Package | 24.04 LTS |
|---|---|
| firefox | Not affected |
| godot | Not affected |
| libwebp | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs60 | Not in release |
| qtimageformats-opensource-src | Not affected |
| qtwebengine-opensource-src | Not affected |
| thunderbird | Not affected |