Search CVE reports


Toggle filters

32151 – 32160 of 62288 results


CVE-2019-13133

Negligible priority
Not affected

ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected
Show less packages

CVE-2019-13127

Medium priority

Not in release

An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated...

1 affected package

mxgraph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mxgraph Not in release
Show less packages

CVE-2019-12781

Medium priority

Some fixes available 4 of 5

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-12970

Medium priority
Fixed

XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail Not in release Not in release
Show less packages

CVE-2019-13118

Low priority

Some fixes available 4 of 5

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt Fixed
Show less packages

CVE-2019-13117

Low priority

Some fixes available 4 of 5

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt Fixed
Show less packages

CVE-2019-13111

Medium priority
Not affected

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

1 affected package

exiv2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Not affected
Show less packages

CVE-2019-13109

Medium priority
Not affected

An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.

1 affected package

exiv2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Not affected
Show less packages

CVE-2019-13108

Medium priority
Not affected

An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.

1 affected package

exiv2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Not affected
Show less packages

CVE-2019-13107

Medium priority
Vulnerable

Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c

1 affected package

libmatio

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmatio Not affected Not affected Not affected Vulnerable
Show less packages