Search CVE reports


Toggle filters

211 – 220 of 881 results


CVE-2017-15413

Medium priority

Some fixes available 6 of 9

Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
oxide-qt Not in release
Show less packages

CVE-2017-15411

Medium priority

Some fixes available 6 of 9

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
oxide-qt Not in release
Show less packages

CVE-2017-15410

Medium priority

Some fixes available 6 of 9

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
oxide-qt Not in release
Show less packages

CVE-2017-15409

Medium priority

Some fixes available 6 of 9

Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
oxide-qt Not in release
Show less packages

CVE-2017-15408

Medium priority

Some fixes available 6 of 9

Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.

2 affected packages

oxide-qt, chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
oxide-qt Not in release
chromium-browser Fixed
Show less packages

CVE-2017-15407

Medium priority

Some fixes available 6 of 9

Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
oxide-qt Not in release
Show less packages

CVE-2018-1999014

Medium priority
Needs evaluation

FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which...

7 affected packages

ffmpeg, qtwebengine-opensource-src, gst-libav1.0, kino, vlc...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Not affected Not affected Not affected Not affected Not affected
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
kino Not in release Not in release Needs evaluation Ignored Ignored
vlc Not affected Not affected Not affected Not affected Not affected
chromium-browser Ignored Ignored Ignored Not in release Ignored
oxide-qt Not in release Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2018-1999013

Medium priority
Needs evaluation

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to...

5 affected packages

gst-libav1.0, qtwebengine-opensource-src, oxide-qt, chromium-browser, ffmpeg

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
oxide-qt Not in release Not in release Not in release Not in release Not in release
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1999012

Medium priority

Some fixes available 1 of 56

FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources...

8 affected packages

chromium-browser, kino, gst-libav1.0, ffmpeg, qtwebengine-opensource-src...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Ignored Not in release Ignored
kino Not in release Not in release Needs evaluation Ignored Ignored
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libav Not in release Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 8 packages Show less packages

CVE-2018-1999011

Medium priority
Needs evaluation

FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears...

6 affected packages

vlc, chromium-browser, ffmpeg, oxide-qt, gst-libav1.0, qtwebengine-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected Not affected
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages