Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2025-0781

Medium priority

Some fixes available 5 of 12

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.

2 affected packages

flightgear, simgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear Not affected Vulnerable Vulnerable Vulnerable Vulnerable
simgear Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2017-13709

Medium priority
Vulnerable

In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.

1 affected package

flightgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-8921

Medium priority
Vulnerable

In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious...

1 affected package

flightgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-9956

Medium priority

Some fixes available 1 of 3

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

1 affected package

flightgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear Not affected Not affected
Show less packages

CVE-2012-2091

Medium priority

Some fixes available 2 of 14

Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long string in a rotor tag...

2 affected packages

flightgear, simgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear
simgear
Show less packages

CVE-2012-2090

Negligible priority
Ignored

Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in...

2 affected packages

flightgear, simgear

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flightgear
simgear
Show less packages