Search CVE reports


Toggle filters

21 – 30 of 31 results


CVE-2020-12135

Medium priority

Some fixes available 15 of 32

bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.

2 affected packages

duo-unix, whoopsie

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
duo-unix Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
whoopsie Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2011-1145

Low priority
Ignored

The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.

1 affected package

unixodbc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unixodbc
Show less packages

CVE-2019-11484

Medium priority

Some fixes available 17 of 34

Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

2 affected packages

duo-unix, whoopsie

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
duo-unix Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
whoopsie Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-4022

Medium priority
Needs evaluation

A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.

1 affected package

mkvtoolnix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mkvtoolnix Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-7485

Medium priority
Not affected

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

1 affected package

unixodbc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unixodbc
Show less packages

CVE-2018-7409

Low priority

Some fixes available 13 of 14

In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

1 affected package

unixodbc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unixodbc Fixed Fixed Fixed
Show less packages

CVE-2016-1515

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8789. Reason: This candidate is a reservation duplicate of CVE-2015-8789. Notes: All CVE users should reference CVE-2015-8789 instead of this candidate. ...

2 affected packages

libebml, mkvtoolnix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libebml
mkvtoolnix
Show less packages

CVE-2016-1514

Low priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8790. Reason: This candidate is a reservation duplicate of CVE-2015-8790. Notes: All CVE users should reference CVE-2015-8790 instead of this candidate. ...

2 affected packages

libebml, mkvtoolnix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libebml
mkvtoolnix
Show less packages

CVE-2012-2658

Low priority
Ignored

Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to...

1 affected package

unixodbc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unixodbc
Show less packages

CVE-2012-2657

Low priority
Ignored

Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be...

1 affected package

unixodbc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unixodbc
Show less packages