Search CVE reports


Toggle filters

161 – 170 of 846 results


CVE-2020-24890

Medium priority
Not affected

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software...

8 affected packages

darktable, dcraw, exactimage, kodi, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Not affected Not affected
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
libraw Not affected Not affected
rawtherapee Not affected Not affected
ufraw Not in release Not affected
xbmc Not in release Not in release
Show all 8 packages Show less packages

CVE-2020-24889

Medium priority
Not affected

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

8 affected packages

libraw, ufraw, darktable, xbmc, dcraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected
ufraw Not in release Not affected
darktable Not affected Not affected
xbmc Not in release Not in release
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
rawtherapee Not affected Not affected
Show all 8 packages Show less packages

CVE-2020-24654

Medium priority
Fixed

In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

1 affected package

ark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ark Fixed Fixed
Show less packages

CVE-2020-17498

Medium priority
Fixed

In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Not affected
Show less packages

CVE-2020-16116

Medium priority

Some fixes available 2 of 3

In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

1 affected package

ark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ark Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-15466

Low priority

Some fixes available 1 of 2

In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Not affected
Show less packages

CVE-2020-15503

Low priority

Some fixes available 2 of 66

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs...

8 affected packages

kodi, libraw, rawtherapee, dcraw, exactimage...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Fixed Fixed
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Ignored Ignored
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2020-5238

Low priority
Needs evaluation

The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a...

5 affected packages

r-cran-commonmark, ruby-commonmarker, cmark-gfm, python-cmarkgfm, haskell-cmark-gfm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
r-cran-commonmark Needs evaluation Needs evaluation Needs evaluation Not in release
ruby-commonmarker Not affected Not affected Needs evaluation Not in release
cmark-gfm Not affected Not affected Ignored Not in release
python-cmarkgfm Needs evaluation Needs evaluation Needs evaluation Not in release
haskell-cmark-gfm Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-15365

Medium priority
Needs evaluation

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

8 affected packages

xbmc, kodi, darktable, libraw, ufraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xbmc Not in release Not in release Not in release Not in release
kodi Needs evaluation Needs evaluation Ignored Ignored
darktable Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
exactimage Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
Show all 8 packages Show less packages

CVE-2020-13164

Low priority

Some fixes available 4 of 5

In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on...

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected Not affected Fixed Fixed
Show less packages