Search CVE reports


Toggle filters

81 – 90 of 109 results

Status is adjusted based on your filters.


CVE-2019-9717

Medium priority
Needs evaluation

In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.

3 affected packages

qtwebengine-opensource-src, gst-libav1.0, ffmpeg

Package 24.04 LTS
qtwebengine-opensource-src Needs evaluation
gst-libav1.0 Needs evaluation
ffmpeg Not affected
Show less packages

CVE-2018-21010

Medium priority
Needs evaluation

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

8 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, gdcm...

Package 24.04 LTS
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
gdcm Not affected
ghostscript Not affected
openjpeg Not in release
openjpeg2 Not affected
Show all 8 packages Show less packages

CVE-2019-2130

Medium priority

In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional...

2 affected packages

chromium-browser, qtwebengine-opensource-src

Package 24.04 LTS
chromium-browser —
qtwebengine-opensource-src —
Show less packages

CVE-2019-2126

Low priority

Some fixes available 1 of 2

In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is...

7 affected packages

qtwebengine-opensource-src, godot, aom, chromium-browser, firefox...

Package 24.04 LTS
qtwebengine-opensource-src Needs evaluation
godot Fixed
aom Not affected
chromium-browser Not affected
firefox Not affected
libvpx Not affected
thunderbird Not affected
Show all 7 packages Show less packages

CVE-2019-12973

Low priority

Some fixes available 1 of 5

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to...

9 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...

Package 24.04 LTS
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
emscripten Ignored
gdcm Not affected
ghostscript Not affected
openjpeg Not in release
openjpeg2 Fixed
Show all 9 packages Show less packages

CVE-2018-20847

Medium priority
Needs evaluation

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

8 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...

Package 24.04 LTS
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
emscripten Ignored
gdcm Not affected
openjpeg Not in release
openjpeg2 Not affected
Show all 8 packages Show less packages

CVE-2018-20846

Medium priority
Needs evaluation

Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service...

8 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...

Package 24.04 LTS
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
emscripten Ignored
gdcm Not affected
openjpeg Not in release
openjpeg2 Not affected
Show all 8 packages Show less packages

CVE-2018-20845

Medium priority
Needs evaluation

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

8 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, emscripten...

Package 24.04 LTS
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
emscripten Ignored
gdcm Not affected
openjpeg Not in release
openjpeg2 Not affected
Show all 8 packages Show less packages

CVE-2019-8457

Medium priority

Some fixes available 2 of 4

SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.

5 affected packages

qtwebengine-opensource-src, sqlcipher, chromium, db5.3, sqlite3

Package 24.04 LTS
qtwebengine-opensource-src Needs evaluation
sqlcipher Vulnerable
chromium Not in release
db5.3 Fixed
sqlite3 Fixed
Show less packages

CVE-2016-9969

Medium priority
Not affected

In libwebp 0.5.1, there is a double free bug in libwebpmux.

9 affected packages

firefox, godot, libwebp, mozjs38, mozjs52...

Package 24.04 LTS
firefox Not affected
godot Not affected
libwebp Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs60 Not in release
qtimageformats-opensource-src Not affected
qtwebengine-opensource-src Not affected
thunderbird Not affected
Show all 9 packages Show less packages