Search CVE reports


Toggle filters

1221 – 1230 of 1318 results


CVE-2013-1764

Medium priority
Not affected

The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.

1 affected package

packagekit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
packagekit
Show less packages

CVE-2014-2030

Medium priority

Some fixes available 3 of 4

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image,...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2014-1958

Medium priority

Some fixes available 3 of 4

Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2013-4453

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

1 affected package

ldap-account-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Not affected Not affected Not affected
Show less packages

CVE-2013-1066

Medium priority
Fixed

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by...

1 affected package

language-selector

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
language-selector
Show less packages

CVE-2013-1441

Medium priority
Ignored

econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.

1 affected package

exactimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage
Show less packages

CVE-2013-4298

Medium priority

Some fixes available 2 of 3

The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF image.

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2013-1438

Medium priority

Some fixes available 42 of 110

Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a...

9 affected packages

rawtherapee, darktable, dcraw, exactimage, libkdcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
darktable Not affected Not affected Not affected Not affected Not affected
dcraw Not affected Not affected Not affected Not affected Vulnerable
exactimage Not affected Not affected Not affected Not affected Not affected
libkdcraw Not affected Not in release Not in release Not in release Not in release
libraw Fixed Fixed Fixed Fixed Fixed
rawstudio Not in release Not in release Not in release Not in release Not in release
ufraw Not in release Not in release Not in release Not in release Fixed
xmbc Not in release Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2012-3437

Medium priority

Some fixes available 4 of 5

The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2012-2736

Medium priority

Some fixes available 6 of 8

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

2 affected packages

network-manager, network-manager-applet

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager
network-manager-applet
Show less packages