Search CVE reports


Toggle filters

561 – 570 of 1313 results


CVE-2020-25266

Medium priority
Needs evaluation

AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.

1 affected package

libappimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libappimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-25265

Medium priority
Needs evaluation

AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.

1 affected package

libappimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libappimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-19667

Low priority
Fixed

Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-25653

Low priority
Fixed

A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting...

1 affected package

spice-vdagent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spice-vdagent Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-25652

Low priority
Fixed

A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user...

1 affected package

spice-vdagent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spice-vdagent Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-25651

Low priority
Fixed

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users...

1 affected package

spice-vdagent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spice-vdagent Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-25650

Low priority
Fixed

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket...

1 affected package

spice-vdagent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spice-vdagent Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-27560

Negligible priority
Fixed

ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-16121

Low priority
Fixed

PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.

1 affected package

packagekit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
packagekit Fixed Fixed
Show less packages

CVE-2020-24890

Medium priority
Not affected

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software...

8 affected packages

darktable, dcraw, exactimage, kodi, libraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Not affected Not affected
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
libraw Not affected Not affected
rawtherapee Not affected Not affected
ufraw Not in release Not affected
xbmc Not in release Not in release
Show all 8 packages Show less packages