Search CVE reports


Toggle filters

1221 – 1230 of 1314 results


CVE-2013-1066

Medium priority
Fixed

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by...

1 affected package

language-selector

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
language-selector
Show less packages

CVE-2013-1441

Medium priority
Ignored

econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.

1 affected package

exactimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage
Show less packages

CVE-2013-4298

Medium priority

Some fixes available 2 of 3

The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF image.

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2013-1438

Medium priority

Some fixes available 42 of 110

Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a...

9 affected packages

rawtherapee, darktable, dcraw, exactimage, libkdcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
darktable Not affected Not affected Not affected Not affected Not affected
dcraw Not affected Not affected Not affected Not affected Vulnerable
exactimage Not affected Not affected Not affected Not affected Not affected
libkdcraw Not affected Not in release Not in release Not in release Not in release
libraw Fixed Fixed Fixed Fixed Fixed
rawstudio Not in release Not in release Not in release Not in release Not in release
ufraw Not in release Not in release Not in release Not in release Fixed
xmbc Not in release Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2012-3437

Medium priority

Some fixes available 4 of 5

The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2012-2736

Medium priority

Some fixes available 6 of 8

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

2 affected packages

network-manager, network-manager-applet

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager
network-manager-applet
Show less packages

CVE-2011-4409

Medium priority
Fixed

The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle...

2 affected packages

ubuntuone-client, ubuntuone-storage-protocol

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ubuntuone-client
ubuntuone-storage-protocol
Show less packages

CVE-2012-0260

Low priority

Some fixes available 1 of 6

The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2012-0950

Medium priority
Fixed

The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to...

1 affected package

update-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
update-manager
Show less packages

CVE-2012-0949

Medium priority
Fixed

The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive files when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a...

1 affected package

update-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
update-manager
Show less packages