Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 30 of 132 results


CVE-2011-4116

Low priority
Ignored

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

2 affected packages

libfile-temp-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libfile-temp-perl
perl
Show less packages

CVE-2019-18218

Medium priority
Fixed

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

1 affected packages

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
file Fixed Fixed
Show less packages

CVE-2019-16680

Medium priority
Fixed

An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

1 affected packages

file-roller

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2019-13147

Medium priority

Some fixes available 7 of 15

In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

1 affected packages

audiofile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
audiofile Vulnerable Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-5429

Low priority
Vulnerable

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

1 affected packages

filezilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
filezilla Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-3832

Low priority
Fixed

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

1 affected packages

libsndfile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libsndfile Not affected Fixed Fixed
Show less packages

CVE-2013-7469

Medium priority
Needs evaluation

Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.

1 affected packages

seafile

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
seafile Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2019-8907

Medium priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

1 affected packages

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
file Fixed Fixed
Show less packages

CVE-2019-8906

Medium priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

1 affected packages

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
file Fixed Not affected
Show less packages

CVE-2019-8905

Low priority
Fixed

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

1 affected packages

file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
file Fixed Fixed
Show less packages