Search CVE reports
331 – 340 of 42162 results
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 18.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | Needs evaluation |
| freerdp3 | — |
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel...
3 affected packages
freerdp, freerdp2, freerdp3
| Package | 18.04 LTS |
|---|---|
| freerdp | Needs evaluation |
| freerdp2 | Needs evaluation |
| freerdp3 | — |
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
1 affected package
wireshark
| Package | 18.04 LTS |
|---|---|
| wireshark | Needs evaluation |
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
1 affected package
wireshark
| Package | 18.04 LTS |
|---|---|
| wireshark | Needs evaluation |
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
1 affected package
wireshark
| Package | 18.04 LTS |
|---|---|
| wireshark | Needs evaluation |
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting...
1 affected package
udisks2
| Package | 18.04 LTS |
|---|---|
| udisks2 | Not affected |
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the...
1 affected package
udisks2
| Package | 18.04 LTS |
|---|---|
| udisks2 | Not affected |
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
1 affected package
curl
| Package | 18.04 LTS |
|---|---|
| curl | Not affected |
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed...
1 affected package
coturn
| Package | 18.04 LTS |
|---|---|
| coturn | Needs evaluation |
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local...
1 affected package
vips
| Package | 18.04 LTS |
|---|---|
| vips | Needs evaluation |