Search CVE reports
11 – 20 of 47870 results
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize...
1 affected package
libde265
| Package | 16.04 LTS |
|---|---|
| libde265 | Needs evaluation |
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in...
1 affected package
libde265
| Package | 16.04 LTS |
|---|---|
| libde265 | Needs evaluation |
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...
2 affected packages
fuse, fuse3
| Package | 16.04 LTS |
|---|---|
| fuse | Needs evaluation |
| fuse3 | — |
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in...
1 affected package
gpac
| Package | 16.04 LTS |
|---|---|
| gpac | Needs evaluation |
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
1 affected package
sogo
| Package | 16.04 LTS |
|---|---|
| sogo | Needs evaluation |
AWStats 8.0 is vulnerable to Command Injection via the open function
1 affected package
awstats
| Package | 16.04 LTS |
|---|---|
| awstats | Needs evaluation |
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From...
1 affected package
deluge
| Package | 16.04 LTS |
|---|---|
| deluge | Needs evaluation |
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into...
1 affected package
deluge
| Package | 16.04 LTS |
|---|---|
| deluge | Needs evaluation |
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000...
1 affected package
pidgin
| Package | 16.04 LTS |
|---|---|
| pidgin | Needs evaluation |
Local unprivileged user can trigger an assert in systemd
1 affected package
systemd
| Package | 16.04 LTS |
|---|---|
| systemd | Not affected |