Search CVE reports


Toggle filters

261 – 270 of 526 results


CVE-2018-18650

Medium priority
Needs evaluation

An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused...

4 affected packages

ipe, libextractor, poppler, xpdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not affected Not in release Not affected
Show less packages

CVE-2018-18459

Negligible priority
Vulnerable

The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18458

Negligible priority
Vulnerable

The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Vulnerable
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18457

Negligible priority
Vulnerable

The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Vulnerable
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18456

Negligible priority
Vulnerable

The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Vulnerable
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18455

Negligible priority
Vulnerable

The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Vulnerable
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18454

Negligible priority
Vulnerable

CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

4 affected packages

xpdf, ipe, libextractor, poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Vulnerable Vulnerable Vulnerable Not in release Vulnerable
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libextractor Not affected Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-3258

Medium priority
Ignored

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network...

1 affected package

mysql-connector-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Not affected
Show less packages

CVE-2018-18385

Medium priority
Vulnerable

Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected...

1 affected package

asciidoctor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asciidoctor Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-16981

Medium priority

Some fixes available 6 of 190

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

13 affected packages

libsixel, love, retroarch, zam-plugins, zynaddsubfx...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsixel Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
love Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
retroarch Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
zam-plugins Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
zynaddsubfx Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsfml Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
goxel Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tweeny Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
catimg Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ccextractor Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
flif Not in release Not in release Not in release Not in release Not in release
mame Vulnerable Fixed Fixed Fixed Fixed
renderdoc Not in release Not in release Needs evaluation Needs evaluation Not in release
Show all 13 packages Show less packages