Search CVE reports


Toggle filters

141 – 150 of 846 results


CVE-2021-43519

Low priority
Needs evaluation

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

45 affected packages

enigma, freeciv, freedroidrpg, fs-uae, golly...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigma Not affected Not affected Not affected Not affected
freeciv Not affected Not affected Not affected Not affected
freedroidrpg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
fs-uae Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golly Needs evaluation Needs evaluation Needs evaluation Needs evaluation
goxel Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2 Not affected Not affected Not affected Not affected
gtk2-engines Not affected Not affected Not affected Not affected
haskell-hslua Not affected Not affected Not affected Not affected
hedgewars Not affected Not affected Not affected Not affected
lua5.1 Not affected Not affected Not affected Not affected
lua5.2 Not affected Not affected Not affected Not affected
lua5.3 Not affected Not affected Not affected Not affected
lua5.4 Not affected Not affected Not in release Not in release
lua50 Not in release Not in release Not affected Not affected
luajit Not affected Not affected Not affected Not affected
mame Not affected Not affected Not affected Not affected
naev Needs evaluation Needs evaluation Needs evaluation
openscenegraph Not affected Not affected Not affected Not affected
redis Not affected Not affected Not affected Not affected
rust-lua52-sys Needs evaluation Needs evaluation Needs evaluation
scite Needs evaluation Needs evaluation Needs evaluation Needs evaluation
scorched3d Needs evaluation Needs evaluation Needs evaluation Needs evaluation
scummvm Not affected Not affected Not affected Not affected
spring Not affected Not affected Not affected Not affected
syslinux Not affected Not affected Not affected Not affected
syslinux-legacy Not in release Not in release Not affected Not affected
tagua Not affected Not affected Not affected Not affected
tarantool Needs evaluation Needs evaluation Needs evaluation
texlive-bin Not affected Not affected Not affected Not affected
tup Needs evaluation Needs evaluation Needs evaluation
ufoai Not affected Not affected Not affected Not affected
vifm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wcc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wesnoth
widelands Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmoto Not affected Not affected Not affected Not affected
zfs-linux Not affected Not affected Not affected Not affected
ardour Not affected Not affected Not affected Not affected
bam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blobby Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ceph Not affected Not affected Not affected Not affected
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eja Not in release Needs evaluation Needs evaluation Needs evaluation
emscripten Needs evaluation Needs evaluation Needs evaluation
Show all 45 packages Show less packages

CVE-2021-22235

Medium priority
Needs evaluation

Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-25017

Medium priority
Vulnerable

RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

2 affected packages

darktable, photoflow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Not affected Not affected Not affected Vulnerable
photoflow Not in release Not affected Not in release Not in release
Show less packages

CVE-2021-22222

Low priority
Needs evaluation

Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-24870

Medium priority
Needs evaluation

Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.

8 affected packages

libraw, ufraw, xbmc, darktable, dcraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2021-22207

Low priority
Needs evaluation

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-22191

Medium priority
Needs evaluation

Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-26813

Medium priority
Needs evaluation

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.

1 affected package

python-markdown2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-markdown2 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2021-22174

Low priority
Needs evaluation

Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-22173

Low priority
Needs evaluation

Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages