Search CVE reports


Toggle filters

81 – 90 of 366 results


CVE-2020-35535

Medium priority
Needs evaluation

In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Not affected Not affected
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
Show all 9 packages Show less packages

CVE-2020-35534

Medium priority
Needs evaluation

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Not affected Not affected
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
Show all 9 packages Show less packages

CVE-2020-35533

Medium priority

Some fixes available 4 of 47

In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Fixed Fixed
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35532

Medium priority

Some fixes available 4 of 47

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Fixed Fixed
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35531

Medium priority

Some fixes available 4 of 47

In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
ufraw Not in release Not in release Not in release Ignored
libraw Not affected Not affected Fixed Fixed
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35530

Medium priority

Some fixes available 4 of 47

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
dcraw Needs evaluation Needs evaluation Ignored Ignored
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Fixed Fixed
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2022-34305

Low priority
Vulnerable

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Not affected
tomcat9 Not affected Vulnerable Vulnerable Not affected
tomcat10 Needs evaluation Not in release Not in release Not in release
Show less packages

CVE-2022-25762

Medium priority
Vulnerable

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue...

2 affected packages

tomcat9, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Not affected Not affected Not affected Vulnerable
tomcat8 Vulnerable
Show less packages

CVE-2022-29885

Low priority

Some fixes available 4 of 7

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network....

5 affected packages

tomcat9, tomcat8, tomcat6, tomcat7, tomcat10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Not affected Fixed Fixed Fixed
tomcat8 Fixed
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Ignored
tomcat10 Needs evaluation Not in release Not in release Not in release
Show less packages

CVE-2022-26635

Medium priority
Ignored

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

1 affected package

php-memcached

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-memcached Not affected Not affected Not affected
Show less packages