Search CVE reports
3471 – 3480 of 44448 results
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow....
1 affected package
mapnik
| Package | 18.04 LTS |
|---|---|
| mapnik | Needs evaluation |
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The...
1 affected package
opencc
| Package | 18.04 LTS |
|---|---|
| opencc | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 18.04 LTS |
|---|---|
| gradle | Needs evaluation |
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...
1 affected package
gradle
| Package | 18.04 LTS |
|---|---|
| gradle | Needs evaluation |
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...
1 affected package
node-tar
| Package | 18.04 LTS |
|---|---|
| node-tar | Needs evaluation |
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
1 affected package
wlc
| Package | 18.04 LTS |
|---|---|
| wlc | Needs evaluation |
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
1 affected package
pyasn1
| Package | 18.04 LTS |
|---|---|
| pyasn1 | Fixed |
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
2 affected packages
request-tracker4, request-tracker5
| Package | 18.04 LTS |
|---|---|
| request-tracker4 | Needs evaluation |
| request-tracker5 | — |
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.
1 affected package
vlc
| Package | 18.04 LTS |
|---|---|
| vlc | Needs evaluation |
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
1 affected package
lemonldap-ng
| Package | 18.04 LTS |
|---|---|
| lemonldap-ng | Needs evaluation |