Search CVE reports
561 – 570 of 53354 results
An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.
1 affected package
redis
| Package | 16.04 LTS |
|---|---|
| redis | Needs evaluation |
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison...
5 affected packages
emacs, xemacs21, xemacs21-packages, emacs24, emacs25
| Package | 16.04 LTS |
|---|---|
| emacs | — |
| xemacs21 | Needs evaluation |
| xemacs21-packages | Needs evaluation |
| emacs24 | Needs evaluation |
| emacs25 | — |
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An...
1 affected package
cpio
| Package | 16.04 LTS |
|---|---|
| cpio | Needs evaluation |
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled...
1 affected package
cpio
| Package | 16.04 LTS |
|---|---|
| cpio | Needs evaluation |
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar...
1 affected package
cpio
| Package | 16.04 LTS |
|---|---|
| cpio | Needs evaluation |
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 16.04 LTS |
|---|---|
| expat | Needs evaluation |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Needs evaluation |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Needs evaluation |
| ayttm | Needs evaluation |
| cableswig | Needs evaluation |
| coin3 | Needs evaluation |
| matanza | Needs evaluation |
| tdom | Needs evaluation |
| vtk | Needs evaluation |
| smart | Needs evaluation |
| firefox | — |
| thunderbird | — |
| libxmltok | Needs evaluation |
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
1 affected package
systemd
| Package | 16.04 LTS |
|---|---|
| systemd | Not affected |