Search CVE reports
151 – 160 of 41631 results
[PSD loader: heap-buffer-overflow in fread_pascal_string() (no null terminator)]
1 affected package
gimp
| Package | 18.04 LTS |
|---|---|
| gimp | Needs evaluation |
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by...
1 affected package
graphicsmagick
| Package | 18.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage...
1 affected package
medusa
| Package | 18.04 LTS |
|---|---|
| medusa | Needs evaluation |
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An...
1 affected package
graphicsmagick
| Package | 18.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial...
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
1 affected package
mongodb
| Package | 18.04 LTS |
|---|---|
| mongodb | Needs evaluation |