VYPR

Ubuntu Linux

by Canonical

CVEs (4,123)

  • CVE-2018-16336MedSep 2, 2018
    risk 0.42cvss 6.5epss 0.03

    Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.

  • CVE-2018-15822HigAug 23, 2018
    risk 0.42cvss 7.5epss 0.03

    The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.

  • CVE-2018-14526MedAug 8, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to…

  • CVE-2018-14883HigAug 3, 2018
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

  • CVE-2018-10903HigJul 30, 2018
    risk 0.42cvss 7.5epss 0.03

    A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a…

  • CVE-2018-14437MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.

  • CVE-2018-14436MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.

  • CVE-2018-14435MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

  • CVE-2018-14434MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.03

    ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

  • CVE-2018-13440MedJul 8, 2018
    risk 0.42cvss 6.5epss 0.03

    The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

  • CVE-2018-1060HigJun 18, 2018
    risk 0.42cvss 7.5epss 0.05

    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

  • CVE-2018-5185MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2018-5169MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

  • CVE-2018-5152MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password…

  • CVE-2018-5133MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes…

  • CVE-2018-5132MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.

  • CVE-2018-5111MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This…

  • CVE-2016-1000338HigJun 1, 2018
    risk 0.42cvss 7.5epss 0.02

    In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the…

  • CVE-2018-11656MedJun 1, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

  • CVE-2018-11655MedJun 1, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.

Page 75 of 207