Search CVE reports
1391 – 1400 of 44409 results
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices....
1 affected package
libgphoto2
| Package | 18.04 LTS |
|---|---|
| libgphoto2 | Needs evaluation |
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function...
1 affected package
libgphoto2
| Package | 18.04 LTS |
|---|---|
| libgphoto2 | Needs evaluation |
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When processing a secondary enumeration list...
1 affected package
libgphoto2
| Package | 18.04 LTS |
|---|---|
| libgphoto2 | Needs evaluation |
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The UINT128 and INT128 cases advance `*offset +=...
1 affected package
libgphoto2
| Package | 18.04 LTS |
|---|---|
| libgphoto2 | Needs evaluation |
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in...
1 affected package
libgphoto2
| Package | 18.04 LTS |
|---|---|
| libgphoto2 | Needs evaluation |
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote....
1 affected package
miniupnpd
| Package | 18.04 LTS |
|---|---|
| miniupnpd | Needs evaluation |
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can...
1 affected package
radare2
| Package | 18.04 LTS |
|---|---|
| radare2 | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters,...
1 affected package
xrdp
| Package | 18.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a...
1 affected package
xrdp
| Package | 18.04 LTS |
|---|---|
| xrdp | Needs evaluation |
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When...
1 affected package
xrdp
| Package | 18.04 LTS |
|---|---|
| xrdp | Needs evaluation |