Search CVE reports
831 – 840 of 38850 results
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG...
1 affected package
gimp
| Package | 26.04 LTS |
|---|---|
| gimp | Needs evaluation |
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 26.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Not in release |
| mozjs115 | Not in release |
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 26.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Not in release |
| mozjs115 | Not in release |
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 26.04 LTS |
|---|---|
| firefox | Not affected |
| thunderbird | Not affected |
| mozjs38 | Not in release |
| mozjs52 | Not in release |
| mozjs68 | Not in release |
| mozjs78 | Not in release |
| mozjs91 | Not in release |
| mozjs102 | Not in release |
| mozjs115 | Not in release |
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated...
1 affected package
python-jwcrypto
| Package | 26.04 LTS |
|---|---|
| python-jwcrypto | Needs evaluation |
[Incomplete fix of CVE-2018-10900]
1 affected package
network-manager-vpnc
| Package | 26.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
[username newline injection reaches a root password helper]
1 affected package
network-manager-vpnc
| Package | 26.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
Not in release
[credential newline injection permits local root code execution]
1 affected package
network-manager-fortisslvpn
| Package | 26.04 LTS |
|---|---|
| network-manager-fortisslvpn | Not in release |
[profile data reaches root pppd pty shell]
1 affected package
network-manager-sstp
| Package | 26.04 LTS |
|---|---|
| network-manager-sstp | Needs evaluation |
[network-manager-iodine: Option confusion reaches iodine's pre-drop root shell]
1 affected package
network-manager-iodine
| Package | 26.04 LTS |
|---|---|
| network-manager-iodine | Needs evaluation |