Search CVE reports


Toggle filters

41 – 43 of 43 results


CVE-2014-4715

Medium priority

Some fixes available 1 of 56

Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory...

10 affected packages

eet, efl, firefox, grub2, gtkwave...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eet — — Not in release Not in release Not in release
efl — — Not affected Not affected Not affected
firefox — — Not affected Not in release Not affected
grub2 — — Not affected Not affected Not affected
gtkwave — — Not affected Not affected Not affected
lz4 — — Not affected Not affected Not affected
php-horde-lz4 — — Not in release Not in release Not affected
pytables — — Not affected Not affected Not affected
thunderbird — — Not affected Not in release Not affected
zfsutils — — Not in release Not in release Not in release
Show all 10 packages Show less packages

CVE-2014-1691

Medium priority
Ignored

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

2 affected packages

horde3, php-horde-util

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
horde3 — — — — —
php-horde-util — — — — —
Show less packages

CVE-2012-6620

Medium priority
Not affected

Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

php-horde-kronolith

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-horde-kronolith — — — — —
Show less packages