Search CVE reports
1 – 10 of 22 results
Some fixes available 28 of 310
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
50 affected packages
coin3, poco, vnc4, vtk, xmlrpc-c...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
poco | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vnc4 | Not in release | Not in release | Not in release | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Fixed | Fixed | Fixed | Fixed |
audacity | Not affected | Not affected | Not affected | Not affected |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
matanza | Ignored | Ignored | Ignored | Ignored |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Fixed | Fixed |
thunderbird | Not affected | Not affected | Not in release | Ignored |
python2.7 | Not in release | Not affected | Not affected | Not affected |
python3.4 | Not in release | Not in release | Not in release | Not in release |
python3.5 | Not in release | Not in release | Not in release | Not in release |
python3.6 | Not in release | Not in release | Not in release | Not affected |
python3.7 | Not in release | Not in release | Not in release | Not affected |
python3.8 | Not in release | Not in release | Not affected | Not affected |
python3.9 | Not in release | Not in release | Not affected | Not in release |
python3.10 | Not in release | Not affected | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
visp | Needs evaluation | Needs evaluation | — | Needs evaluation |
astropy | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
emboss | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
paraview | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ibm-3270 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
coda | Needs evaluation | Needs evaluation | Needs evaluation | — |
mame | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
opencollada | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
harp | Needs evaluation | Needs evaluation | Needs evaluation | — |
tla | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libsynthesis | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
xsd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
sitecopy | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
insighttoolkit5 | Needs evaluation | Needs evaluation | — | — |
xmlrpc | — | — | — | — |
Some fixes available 3 of 9
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au...
1 affected package
audacity
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | Not affected | Not affected | Fixed | Fixed |
Some fixes available 56 of 189
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a...
32 affected packages
coin3, vnc4, xmlrpc-c, libxmltok, audacity...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Vulnerable |
vnc4 | Not in release | Not in release | Not in release | Vulnerable |
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
libxmltok | Fixed | Fixed | Fixed | Fixed |
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Not affected | Not affected | Not affected | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
poco | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kompozer | Not in release | Not in release | Not in release | Not in release |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
simgear | Not affected | Not affected | Not affected | Not affected |
tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Fixed | Fixed | Fixed | Fixed |
thunderbird | Fixed | Fixed | Fixed | Fixed |
chromium-browser | Fixed | Fixed | Fixed | Fixed |
Some fixes available 25 of 121
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...
32 affected packages
coin3, vnc4, xmlrpc-c, libxmltok, audacity...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Not affected | Not affected | Not affected | Vulnerable |
vnc4 | Not in release | Not in release | Not in release | Vulnerable |
xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libxmltok | Fixed | Fixed | Fixed | Fixed |
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
expat | Fixed | Fixed | Fixed | Fixed |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
poco | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kompozer | Not in release | Not in release | Not in release | Not in release |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
simgear | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
smart | Not in release | Not in release | Not in release | Not affected |
firefox | Not affected | Not affected | Not in release | Not affected |
thunderbird | Not affected | Not affected | Not in release | Not affected |
Some fixes available 7 of 99
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
33 affected packages
audacity, matanza, cadaver, cmake, firefox...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
cadaver | Not affected | Not affected | Not affected | Not affected |
cmake | Not affected | Not affected | Not affected | Not affected |
firefox | Not affected | Not affected | Not in release | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
insighttoolkit4 | Not in release | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
tdom | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
thunderbird | Not affected | Not affected | Not in release | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
expat | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
xmlrpc-c | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
vnc4 | Not in release | Not in release | Not in release | Ignored |
poco | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
gdcm | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
coin3 | Not affected | Not affected | Not affected | Needs evaluation |
vtk | Not in release | Not in release | Not in release | Not in release |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
1 affected package
audacity
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | — | — | — | — |
Some fixes available 5 of 99
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this...
31 affected packages
xmlrpc-c, audacity, ayttm, cableswig, cmake...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
audacity | Not affected | Not affected | Not affected | Not affected |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
cmake | Not affected | Not affected | Not affected | Not affected |
ghostscript | Not affected | Not affected | Not affected | Not affected |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
matanza | Not affected | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
sitecopy | Not in release | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
swish-e | Not affected | Not affected | Not affected | Not affected |
tdom | Not affected | Not affected | Not affected | Not affected |
texlive-bin | Not affected | Not affected | Not affected | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
xotcl | Not affected | Not affected | Not affected | Not affected |
expat | Not affected | Not affected | Not affected | Not affected |
apache2 | Not affected | Not affected | Not affected | Not affected |
apr-util | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
vnc4 | Not in release | Not in release | Not in release | Ignored |
poco | Not affected | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
cadaver | Not affected | Not affected | Not affected | Not affected |
gdcm | Not affected | Not affected | Not affected | Not affected |
coin3 | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
libxmltok | Not affected | Not affected | Not affected | Not affected |
Some fixes available 7 of 174
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this...
26 affected packages
coin3, xmlrpc-c, libxmltok, audacity, matanza...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
coin3 | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
xmlrpc-c | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
libxmltok | Fixed | Fixed | Fixed | Fixed |
audacity | Not affected | Not affected | Not affected | Not affected |
matanza | Ignored | Ignored | Ignored | Ignored |
ayttm | Not in release | Not in release | Not in release | Not in release |
cableswig | Not in release | Not in release | Not in release | Not in release |
cadaver | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
insighttoolkit | Not in release | Not in release | Not in release | Not in release |
sitecopy | Not in release | Not affected | Not affected | Not affected |
smart | Not in release | Not in release | Not in release | Not affected |
swish-e | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
tdom | Not affected | Not affected | Not affected | Not affected |
tla | Not affected | Not affected | Not affected | Not affected |
wbxml2 | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.8 | Not in release | Not in release | Not in release | Not in release |
xotcl | Not affected | Not affected | Not affected | Not affected |
expat | Not affected | Not affected | Not affected | Not affected |
wxwidgets2.6 | Not in release | Not in release | Not in release | Not in release |
vnc4 | Not in release | Not in release | Not in release | Ignored |
poco | Not affected | Not affected | Not affected | Not affected |
libparagui1.1 | Not in release | Not in release | Not in release | Not in release |
kompozer | Not in release | Not in release | Not in release | Not in release |
gdcm | Not affected | Not affected | Not affected | Not affected |
simgear | Not affected | Not affected | Not affected | Not affected |
vtk | Not in release | Not in release | Not in release | Not in release |
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
1 affected package
audacity
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | — | — | — | Not affected |
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure.
1 affected package
audacity
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
audacity | — | — | — | Not affected |