Search CVE reports


Toggle filters

31 – 40 of 155 results


CVE-2021-4156

Low priority

Some fixes available 5 of 9

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and...

1 affected package

libsndfile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-24599

Low priority

Some fixes available 7 of 9

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the...

1 affected package

audiofile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
audiofile Fixed Fixed Fixed
Show less packages

CVE-2021-43820

Medium priority
Not affected

Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a...

1 affected package

seafile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seafile Not affected Not affected Not affected
Show less packages

CVE-2021-3246

Medium priority

Some fixes available 7 of 8

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

1 affected package

libsndfile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Fixed Fixed Fixed
Show less packages

CVE-2009-0948

Medium priority
Not affected

Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.

1 affected package

file

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2009-0947

Medium priority
Not affected

Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.

1 affected package

file

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
Show less packages

CVE-2020-36314

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain...

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages

CVE-2021-30146

Medium priority
Needs evaluation

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

1 affected package

seafile-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seafile-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-18925

Medium priority
Needs evaluation

opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

1 affected package

opentmpfiles

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opentmpfiles Not in release Not in release Not in release Needs evaluation Not in release
Show less packages

CVE-2020-11736

Medium priority
Fixed

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Fixed Fixed
Show less packages