Search CVE reports


Toggle filters

1211 – 1220 of 1369 results


CVE-2015-8367

Low priority

Some fixes available 1 of 95

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

8 affected packages

exactimage, rawtherapee, kodi, darktable, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Vulnerable Vulnerable Vulnerable
darktable Not affected Not affected Not affected Not affected Not affected
dcraw Not affected Not affected Not affected Not affected Not affected
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2015-8366

Low priority

Some fixes available 1 of 117

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Not in release Not affected
darktable Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
dcraw Not affected Not affected Not affected Not affected Vulnerable
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Vulnerable Vulnerable Vulnerable
libraw Not affected Not affected Not affected Not affected Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2015-2924

Low priority
Ignored

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value...

1 affected package

network-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager — — — — —
Show less packages

CVE-2015-0852

Medium priority

Some fixes available 1 of 7

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

1 affected package

freeimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeimage — — Not affected Not affected Not affected
Show less packages

CVE-2015-0272

Medium priority

Some fixes available 8 of 30

GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.

100 affected packages

linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux, linux-armadaxp...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux-aws-fips — Not in release Not affected Not affected Not affected
linux-azure-fips — Not in release Not affected Not affected Not affected
linux-gcp-fips — Not in release Not affected Not affected Not affected
linux — Not affected Not affected Not affected Not affected
linux-armadaxp — — — — —
linux-aws — Not affected Not affected Not affected Not affected
linux-aws-5.15 — Not in release Not in release Not affected Not in release
linux-aws-5.4 — Not in release Not in release Not in release Not affected
linux-aws-6.14 — Not affected Not in release Not in release Not in release
linux-aws-6.8 — Not in release Not affected Not in release Not in release
linux-aws-hwe — Not in release Not in release Not in release Not in release
linux-azure — Not affected Not affected Not affected Ignored
linux-azure-4.15 — Not in release Not in release Not in release Not affected
linux-azure-5.15 — Not in release Not in release Not affected Not in release
linux-azure-5.4 — Not in release Not in release Not in release Not affected
linux-azure-6.11 — Ignored Not in release Not in release Not in release
linux-azure-6.8 — Not in release Not affected Not in release Not in release
linux-azure-fde — Not affected Not affected Ignored Not in release
linux-azure-fde-5.15 — Not in release Not in release Ignored Not in release
linux-azure-nvidia — Not affected Not in release Not in release Not in release
linux-bluefield — Not in release Not in release Not affected Not in release
linux-fips — Not in release Not affected Not affected Not affected
linux-flo — — — — —
linux-gcp — Not affected Not affected Not affected Ignored
linux-gcp-4.15 — Not in release Not in release Not in release Not affected
linux-gcp-5.15 — Not in release Not in release Not affected Not in release
linux-gcp-5.4 — Not in release Not in release Not in release Not affected
linux-gcp-6.11 — Ignored Not in release Not in release Not in release
linux-gcp-6.14 — Not affected Not in release Not in release Not in release
linux-gcp-6.8 — Not in release Not affected Not in release Not in release
linux-gke — Not affected Not affected Ignored Not in release
linux-gkeop — Not affected Not affected Ignored Not in release
linux-goldfish — — — — —
linux-grouper — — — — —
linux-hwe — Not in release Not in release Not in release Ignored
linux-hwe-5.15 — Not in release Not in release Not affected Not in release
linux-hwe-5.4 — Not in release Not in release Not in release Not affected
linux-hwe-6.11 — Ignored Not in release Not in release Not in release
linux-hwe-6.14 — Not affected Not in release Not in release Not in release
linux-hwe-6.8 — Not in release Not affected Not in release Not in release
linux-hwe-edge — Not in release Not in release Not in release Ignored
linux-ibm — Not affected Not affected Not affected Not in release
linux-ibm-5.15 — Not in release Not in release Not affected Not in release
linux-ibm-5.4 — Not in release Not in release Not in release Not affected
linux-ibm-6.8 — Not in release Not affected Not in release Not in release
linux-intel — Not affected Not in release Not in release Not in release
linux-intel-iot-realtime — Not in release Not affected Not in release Not in release
linux-intel-iotg — Not in release Not affected Not in release Not in release
linux-intel-iotg-5.15 — Not in release Not in release Not affected Not in release
linux-iot — Not in release Not in release Not affected Not in release
linux-kvm — Not in release Not affected Not affected Not affected
linux-linaro-omap — — — — —
linux-linaro-shared — — — — —
linux-linaro-vexpress — — — — —
linux-lowlatency — Not affected Not affected Not in release Not in release
linux-lowlatency-hwe-5.15 — Not in release Not in release Not affected Not in release
linux-lowlatency-hwe-6.11 — Ignored Not in release Not in release Not in release
linux-lowlatency-hwe-6.8 — Not in release Not affected Not in release Not in release
linux-lts-quantal — — — — —
linux-lts-raring — — — — —
linux-lts-saucy — — — — —
linux-lts-trusty — — — — —
linux-lts-utopic — — — — —
linux-lts-vivid — — — — —
linux-lts-wily — — — — —
linux-lts-xenial — Not in release Not in release Not in release Not in release
linux-maguro — — — — —
linux-mako — — — — —
linux-manta — — — — —
linux-nvidia — Not affected Not affected Not in release Not in release
linux-nvidia-6.11 — Not affected Not in release Not in release Not in release
linux-nvidia-6.8 — Not in release Not affected Not in release Not in release
linux-nvidia-lowlatency — Not affected Not in release Not in release Not in release
linux-nvidia-tegra — Not affected Not affected Not in release Not in release
linux-nvidia-tegra-5.15 — Not in release Not in release Not affected Not in release
linux-nvidia-tegra-igx — Not in release Not affected Not in release Not in release
linux-oem-6.11 — Not affected Not in release Not in release Not in release
linux-oem-6.14 — Not affected Not in release Not in release Not in release
linux-oem-6.8 — Not affected Not in release Not in release Not in release
linux-oracle — Not affected Not affected Not affected Not affected
linux-oracle-5.15 — Not in release Not in release Not affected Not in release
linux-oracle-5.4 — Not in release Not in release Not in release Not affected
linux-oracle-6.14 — Not affected Not in release Not in release Not in release
linux-oracle-6.8 — Not in release Not affected Not in release Not in release
linux-qcm-msm — — — — —
linux-raspi — Not affected Not affected Not affected Not in release
linux-raspi-5.4 — Not in release Not in release Not in release Not affected
linux-raspi-realtime — Not affected Not in release Not in release Not in release
linux-raspi2 — Not in release Not in release Ignored Ignored
linux-realtime — Not affected Not affected Not in release Not in release
linux-realtime-6.14 — Not affected Not in release Not in release Not in release
linux-realtime-6.8 — Not in release Not affected Not in release Not in release
linux-riscv — Ignored Ignored Ignored Not in release
linux-riscv-5.15 — Not in release Not in release Not affected Not in release
linux-riscv-6.14 — Not affected Not in release Not in release Not in release
linux-riscv-6.8 — Not in release Not affected Not in release Not in release
linux-snapdragon — Not in release Not in release Not in release Ignored
linux-ti-omap4 — — — — —
linux-xilinx-zynqmp — Not in release Not affected Not affected Not in release
network-manager — Not affected Not affected Not affected Not affected
Show all 100 packages Show less packages

CVE-2015-3885

Negligible priority

Some fixes available 2 of 54

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

10 affected packages

dcraw, kodi, darktable, exactimage, freeimage...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Not affected Not affected Not affected Not affected Not affected
kodi Needs evaluation Needs evaluation Not affected Not affected Not affected
darktable Not affected Not affected Not affected Not affected Not affected
exactimage Not affected Not affected Not affected Not affected Not affected
freeimage Not affected Not affected Not affected Not affected Not affected
libraw Not affected Not affected Not affected Not affected Not affected
rawstudio Not in release Not in release Not in release Not in release Not in release
rawtherapee Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 10 packages Show less packages

CVE-2015-1322

Medium priority

Some fixes available 3 of 4

Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local users to...

1 affected package

network-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager — — — — —
Show less packages

CVE-2015-1589

Medium priority

Some fixes available 1 of 4

Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot dot) in a CHM file.

1 affected package

archmage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
archmage — — — — Not affected
Show less packages

CVE-2014-1425

Medium priority
Fixed

cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.

1 affected package

cgmanager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cgmanager — — — — —
Show less packages

CVE-2014-9854

Medium priority
Fixed

coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick — — — — —
Show less packages