Search CVE reports


Toggle filters

91 – 100 of 216 results


CVE-2022-35060

Negligible priority
Ignored

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.

1 affected package

texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-40674

Medium priority

Some fixes available 15 of 127

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

24 affected packages

ayttm, cableswig, cadaver, coin3, insighttoolkit...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ayttm Not in release Not in release Not in release
cableswig Not in release Not in release Not in release
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
coin3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit Not in release Not in release Not in release
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
smart Not in release Not in release Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
thunderbird Ignored Ignored Ignored Not in release Ignored
vnc4 Not in release Not in release Needs evaluation
vtk Not in release Not in release Not in release
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed Fixed
firefox Not affected Not affected Not affected Fixed Fixed
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
libxmltok Not in release Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored Ignored
texlive-bin Not affected Not affected Not affected Not affected Not affected
Show all 24 packages Show less packages

CVE-2022-36561

Low priority
Needs evaluation

XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.

4 affected packages

xpdf, ipe, texlive-bin, emscripten

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not affected Not in release Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texlive-bin Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emscripten Needs evaluation Needs evaluation Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2022-24107

Medium priority

Some fixes available 2 of 31

Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

4 affected packages

xpdf, ipe, emscripten, texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not affected Not in release Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emscripten Needs evaluation Needs evaluation Needs evaluation Not in release Needs evaluation
texlive-bin Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2022-24106

Medium priority

Some fixes available 2 of 31

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

4 affected packages

xpdf, ipe, emscripten, texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not affected Not in release Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emscripten Needs evaluation Needs evaluation Needs evaluation Not in release Needs evaluation
texlive-bin Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2022-38171

Medium priority
Needs evaluation

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of...

3 affected packages

xpdf, ipe, texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not affected Not affected Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texlive-bin Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-35486

Negligible priority
Ignored

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.

1 affected package

texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-35485

Negligible priority
Ignored

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.

1 affected package

texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-35484

Negligible priority
Ignored

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.

1 affected package

texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-35483

Negligible priority
Ignored

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.

1 affected package

texlive-bin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected Not affected Not affected Not affected
Show less packages