Search CVE reports
201 – 210 of 881 results
Some fixes available 3 of 4
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
Some fixes available 3 of 4
A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4,...
7 affected packages
vlc, gst-libav1.0, mythtv, libav, oxide-qt...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vlc | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
chromium-browser | Ignored | Ignored | Not in release | Ignored |
In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a...
12 affected packages
chromium-browser, kino, mplayer, dvbcut, gst-libav1.0...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
mplayer | Not affected | Not affected | Not affected | Not affected |
dvbcut | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release |
xine-lib | Not in release | Not in release | Not in release | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4,...
10 affected packages
chromium-browser, ffmpeg, gst-libav1.0, kino, mythtv...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release |
libav | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
mplayer | Not affected | Not affected | Not affected | Not affected |
vlc | Not affected | Not affected | Not affected | Not affected |
Some fixes available 16 of 82
In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while...
10 affected packages
chromium-browser, ffmpeg, gst-libav1.0, kino, mythtv...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Fixed | Fixed | Fixed | Fixed |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release |
mplayer | Not affected | Not affected | Not affected | Not affected |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected |
In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to...
9 affected packages
chromium-browser, libav, gstreamer0.10-ffmpeg, vlc, gst-libav1.0...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
libav | Not in release | Not in release | Not in release | Not in release |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
mplayer | Not affected | Not affected | Not affected | Not affected |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
Some fixes available 15 of 81
In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI...
10 affected packages
chromium-browser, ffmpeg, gstreamer0.10-ffmpeg, mplayer, vlc...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Fixed | Fixed | Fixed | Fixed |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release |
mplayer | Not affected | Not affected | Not affected | Not affected |
vlc | Not affected | Not affected | Not affected | Not affected |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
Some fixes available 6 of 11
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial...
4 affected packages
sqlite, sqlite3, chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
sqlite | — | — | — | Not affected |
sqlite3 | — | — | — | Not affected |
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
Some fixes available 3 of 31
An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
6 affected packages
android, flac, praat, chromium-browser, mame, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
android | Not in release | Not in release | Not in release | Not in release |
flac | Not affected | Not affected | Not affected | Fixed |
praat | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
chromium-browser | Not affected | Not affected | Not in release | Not affected |
mame | Not affected | Not affected | Not affected | Not affected |
oxide-qt | Not in release | Not in release | Not in release | Not in release |