Search CVE reports
531 – 540 of 59015 results
Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within...
1 affected package
libimager-perl
| Package | 16.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a NUL byte...
1 affected package
hamlib
| Package | 16.04 LTS |
|---|---|
| hamlib | Needs evaluation |
PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine...
1 affected package
libpodofo
| Package | 16.04 LTS |
|---|---|
| libpodofo | Needs evaluation |
JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query...
1 affected package
jabref
| Package | 16.04 LTS |
|---|---|
| jabref | Needs evaluation |
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or...
1 affected package
openimageio
| Package | 16.04 LTS |
|---|---|
| openimageio | Needs evaluation |
OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a...
1 affected package
openslide
| Package | 16.04 LTS |
|---|---|
| openslide | Needs evaluation |
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled...
1 affected package
mapserver
| Package | 16.04 LTS |
|---|---|
| mapserver | Needs evaluation |
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric...
1 affected package
mapserver
| Package | 16.04 LTS |
|---|---|
| mapserver | Needs evaluation |
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana...
1 affected package
openslide
| Package | 16.04 LTS |
|---|---|
| openslide | Needs evaluation |
Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains...
1 affected package
elixir
| Package | 16.04 LTS |
|---|---|
| elixir | Needs evaluation |