Search CVE reports


Toggle filters

61 – 70 of 81 results


CVE-2018-20843

Low priority

Some fixes available 27 of 131

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable...

32 affected packages

xmlrpc-c, vnc4, sitecopy, swish-e, insighttoolkit...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vnc4 Not in release Not in release Not in release Not in release Vulnerable
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit Not in release Not in release Not in release Not in release Not in release
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ayttm Not in release Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release Not in release
coin3 Not affected Not affected Not affected Not affected Vulnerable
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
audacity Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed Fixed
firefox Not affected Not affected Not affected Not in release Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Fixed Fixed Fixed Fixed
matanza Ignored Ignored Ignored Ignored Ignored
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not affected Not in release Not affected
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
Show all 32 packages Show less packages

CVE-2019-9628

Medium priority
Fixed

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was...

1 affected package

xmltooling

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmltooling — — — — Fixed
Show less packages

CVE-2018-0489

High priority

Some fixes available 2 of 3

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information...

1 affected package

xmltooling

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmltooling — — — — Not affected
Show less packages

CVE-2018-0486

Medium priority

Some fixes available 2 of 4

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive...

1 affected package

xmltooling

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmltooling — — — — Not affected
Show less packages

CVE-2017-9233

Medium priority

Some fixes available 7 of 103

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

33 affected packages

sitecopy, swish-e, insighttoolkit4, cableswig, apache2...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Not affected Not affected Not affected
cableswig Not in release Not in release Not in release Not in release Not in release
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
audacity Not affected Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release Not in release
cadaver Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Not affected Needs evaluation
expat Not affected Not affected Not affected Not affected Not affected
firefox Not affected Not affected Not affected Not in release Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release Not in release
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored Ignored
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not affected Not in release Not affected
tla Not in release Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Not in release Ignored
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
xmlrpc-c Not affected Not affected Not affected Not affected Not affected
Show all 33 packages Show less packages

CVE-2016-5300

Medium priority

Some fixes available 5 of 103

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this...

31 affected packages

xmlrpc-c, sitecopy, apache2, apr-util, audacity...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
audacity Not affected Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release Not in release
cadaver Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Not affected Not affected
expat Not affected Not affected Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release Not in release
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Not affected Not affected Not affected Not affected
matanza Not affected Not affected Not affected Not affected Not affected
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
swish-e Not affected Not affected Not affected Not affected Not affected
tdom Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
tla Not in release Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Not in release Ignored
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
xotcl Not affected Not affected Not affected Not affected Not affected
Show all 31 packages Show less packages

CVE-2016-4472

Medium priority

Some fixes available 7 of 184

The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this...

26 affected packages

xmlrpc-c, sitecopy, swish-e, insighttoolkit, cadaver...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
swish-e Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
insighttoolkit Not in release Not in release Not in release Not in release Not in release
cadaver Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
ayttm Not in release Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release Not in release
coin3 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
audacity Not affected Not affected Not affected Not affected Not affected
expat Not affected Not affected Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Fixed Fixed Fixed Fixed
matanza Ignored Ignored Ignored Ignored Ignored
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected Not affected
tla Not in release Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Not in release Ignored
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
xotcl Not affected Not affected Not affected Not affected Not affected
Show all 26 packages Show less packages

CVE-2016-0718

Medium priority

Some fixes available 34 of 211

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

28 affected packages

xmlrpc-c, sitecopy, swish-e, insighttoolkit, cadaver...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
swish-e Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
insighttoolkit Not in release Not in release Not in release Not in release Not in release
cadaver Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
ayttm Not in release Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release Not in release
coin3 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
audacity Not affected Not affected Not affected Not affected Not affected
expat Fixed Fixed Fixed Fixed Fixed
firefox Not affected Not affected Not affected Not in release Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Fixed Fixed Fixed Fixed
matanza Ignored Ignored Ignored Ignored Ignored
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not affected Not in release Not affected
tla Not in release Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Not in release Ignored
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
xotcl Not affected Not affected Not affected Not affected Not affected
Show all 28 packages Show less packages

CVE-2015-0851

Medium priority

Some fixes available 2 of 9

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

2 affected packages

opensaml2, xmltooling

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensaml2 — — — — Not affected
xmltooling — — — — Not affected
Show less packages

CVE-2015-1283

Medium priority

Some fixes available 43 of 260

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or...

33 affected packages

xmlrpc-c, sitecopy, swish-e, insighttoolkit, cadaver...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
sitecopy Needs evaluation Not in release Not affected Not affected Not affected
swish-e Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
insighttoolkit Not in release Not in release Not in release Not in release Not in release
cadaver Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
ayttm Not in release Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release Not in release
coin3 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
audacity Not affected Not affected Not affected Not affected Not affected
chromium-browser Fixed Fixed Fixed Fixed Fixed
cmake Not affected Not affected Not affected Not affected Not affected
expat Not affected Not affected Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
kompozer Not in release Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release Not in release
libxmltok Not in release Fixed Fixed Fixed Fixed
matanza Ignored Ignored Ignored Ignored Ignored
oxide-qt Not in release Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected Not affected
simgear Not affected Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
tla Not in release Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Not in release Vulnerable
vtk Not in release Not in release Not in release Not in release Not in release
wbxml2 Not affected Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release Not in release
wxwidgets2.8 Not in release Not in release Not in release Not in release Not in release
xotcl Not affected Not affected Not affected Not affected Not affected
Show all 33 packages Show less packages