VYPR

Ubuntu Linux

by Canonical

CVEs (4,123)

  • CVE-2018-14434MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.03

    ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

  • CVE-2018-13440MedJul 8, 2018
    risk 0.42cvss 6.5epss 0.03

    The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

  • CVE-2018-1060HigJun 18, 2018
    risk 0.42cvss 7.5epss 0.05

    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

  • CVE-2018-5185MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2018-5169MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

  • CVE-2018-5152MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password…

  • CVE-2018-5133MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes…

  • CVE-2018-5132MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.

  • CVE-2018-5111MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This…

  • CVE-2016-1000338HigJun 1, 2018
    risk 0.42cvss 7.5epss 0.02

    In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the…

  • CVE-2018-11656MedJun 1, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

  • CVE-2018-11655MedJun 1, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.

  • CVE-2017-18273MedMay 18, 2018
    risk 0.42cvss 6.5epss 0.03

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.

  • CVE-2017-18271MedMay 18, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.

  • CVE-2018-11214MedMay 16, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

  • CVE-2018-11213MedMay 16, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

  • CVE-2018-10999MedMay 12, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.

  • CVE-2018-10998MedMay 12, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.

  • CVE-2018-10958MedMay 10, 2018
    risk 0.42cvss 6.5epss 0.03

    In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.

  • CVE-2018-10805MedMay 8, 2018
    risk 0.42cvss 6.5epss 0.02

    ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

Page 75 of 207