Search CVE reports


Toggle filters

31 – 40 of 151 results


CVE-2009-0948

Medium priority
Not affected

Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.

1 affected package

file

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2009-0947

Medium priority
Not affected

Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.

1 affected package

file

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2020-36314

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain...

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2021-30146

Medium priority
Needs evaluation

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

1 affected package

seafile-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seafile-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-18925

Medium priority
Needs evaluation

opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

1 affected package

opentmpfiles

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opentmpfiles Not in release Not in release Not in release Needs evaluation Not in release
Show less packages

CVE-2020-11736

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2011-4116

Low priority
Ignored

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

2 affected packages

libfile-temp-perl, perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfile-temp-perl
perl
Show less packages

CVE-2019-18218

Medium priority
Fixed

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

1 affected package

file

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Fixed
Show less packages

CVE-2019-16680

Medium priority
Fixed

An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed
Show less packages

CVE-2019-13147

Medium priority

Some fixes available 7 of 19

In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

1 affected package

audiofile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Vulnerable Vulnerable Fixed Fixed Fixed
Show less packages