Search CVE reports
1201 – 1210 of 58108 results
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component....
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions....
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract...
1 affected package
tesseract
| Package | 16.04 LTS |
|---|---|
| tesseract | Needs evaluation |
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled...
1 affected package
gvfs
| Package | 16.04 LTS |
|---|---|
| gvfs | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory...
1 affected package
suricata
| Package | 16.04 LTS |
|---|---|
| suricata | Needs evaluation |
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...
1 affected package
node-cookies
| Package | 16.04 LTS |
|---|---|
| node-cookies | Needs evaluation |
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript...
1 affected package
evolution
| Package | 16.04 LTS |
|---|---|
| evolution | Needs evaluation |