Search CVE reports
1171 – 1180 of 49291 results
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG...
1 affected package
gimp
| Package | 20.04 LTS |
|---|---|
| gimp | Needs evaluation |
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; ...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 20.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | — |
| openjdk-lts | Needs evaluation |
| openjdk-13 | Ignored |
| openjdk-16 | Ignored |
| openjdk-17 | Needs evaluation |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | Needs evaluation |
| openjdk-21-crac | — |
| openjdk-25 | — |
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 20.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | — |
| openjdk-lts | Needs evaluation |
| openjdk-13 | Ignored |
| openjdk-16 | Ignored |
| openjdk-17 | Needs evaluation |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | Needs evaluation |
| openjdk-21-crac | — |
| openjdk-25 | — |
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; ...
11 affected packages
openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...
| Package | 20.04 LTS |
|---|---|
| openjdk-8 | Needs evaluation |
| openjdk-9 | — |
| openjdk-lts | Needs evaluation |
| openjdk-13 | Ignored |
| openjdk-16 | Ignored |
| openjdk-17 | Needs evaluation |
| openjdk-17-crac | — |
| openjdk-18 | — |
| openjdk-21 | Needs evaluation |
| openjdk-21-crac | — |
| openjdk-25 | — |
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a...
2 affected packages
docker.io, docker.io-app
| Package | 20.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 20.04 LTS |
|---|---|
| firefox | — |
| thunderbird | — |
| mozjs38 | — |
| mozjs52 | Ignored |
| mozjs68 | Ignored |
| mozjs78 | — |
| mozjs91 | — |
| mozjs102 | — |
| mozjs115 | — |
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 20.04 LTS |
|---|---|
| firefox | — |
| thunderbird | — |
| mozjs38 | — |
| mozjs52 | Ignored |
| mozjs68 | Ignored |
| mozjs78 | — |
| mozjs91 | — |
| mozjs102 | — |
| mozjs115 | — |
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 20.04 LTS |
|---|---|
| firefox | — |
| thunderbird | — |
| mozjs38 | — |
| mozjs52 | Ignored |
| mozjs68 | Ignored |
| mozjs78 | — |
| mozjs91 | — |
| mozjs102 | — |
| mozjs115 | — |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the...
1 affected package
virtualbox
| Package | 20.04 LTS |
|---|---|
| virtualbox | Needs evaluation |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the...
1 affected package
virtualbox
| Package | 20.04 LTS |
|---|---|
| virtualbox | Needs evaluation |