Search CVE reports


Toggle filters

71 – 75 of 75 results

Status is adjusted based on your filters.


CVE-2012-0876

Medium priority

Some fixes available 1 of 4

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption)...

41 affected packages

paraview, sitecopy, swish-e, insighttoolkit, cadaver...

Package 20.04 LTS
paraview Not affected
sitecopy Not affected
swish-e Vulnerable
insighttoolkit Not in release
cadaver Vulnerable
ayttm Not in release
cableswig Not in release
coin3 Not affected
apache2 Not affected
apr-util Not affected
audacity Not affected
celementtree Not in release
cmake Not affected
expat Not affected
gdcm Not affected
ghostscript Not affected
grmonitor Not in release
kompozer Not in release
libparagui1.1 Not in release
libxmltok Not affected
matanza Ignored
poco Not affected
python-xml Not in release
python2.4 Not in release
python2.5 Not in release
python2.6 Not in release
simgear Not affected
smart Not in release
tdom Not affected
texlive-bin Not affected
tla Not affected
vnc4 Not in release
vtk Not in release
w3c-libwww Not in release
wbxml2 Not affected
wxwidgets2.6 Not in release
wxwidgets2.8 Not in release
wxwindows2.4 Not in release
xmlrpc-c Fixed
xotcl Not affected
xulrunner Not in release
Show all 41 packages Show less packages

CVE-2009-3560

Medium priority

Some fixes available 2 of 4

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed...

41 affected packages

sitecopy, swish-e, cableswig, coin3, apache2...

Package 20.04 LTS
sitecopy Not affected
swish-e Needs evaluation
cableswig Not in release
coin3 Not affected
apache2 Not affected
apr-util Not affected
audacity Not affected
ayttm Not in release
cadaver Not affected
celementtree Not in release
cmake Not affected
expat Fixed
gdcm Not affected
ghostscript Not affected
grmonitor Not in release
insighttoolkit Not in release
kompozer Not in release
libparagui1.1 Not in release
libxmltok Not affected
matanza Ignored
paraview Not affected
poco Not affected
python-xml Not in release
python2.4 Not in release
python2.5 Not in release
python2.6 Not in release
simgear Not affected
smart Not in release
tdom Not affected
texlive-bin Not affected
tla Not affected
vnc4 Not in release
vtk Not in release
w3c-libwww Not in release
wbxml2 Not affected
wxwidgets2.6 Not in release
wxwidgets2.8 Not in release
wxwindows2.4 Not in release
xmlrpc-c Fixed
xotcl Not affected
xulrunner Not in release
Show all 41 packages Show less packages

CVE-2009-3720

Low priority

Some fixes available 2 of 6

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML...

41 affected packages

sitecopy, swish-e, insighttoolkit, cadaver, cableswig...

Package 20.04 LTS
sitecopy Not affected
swish-e Needs evaluation
insighttoolkit Not in release
cadaver Vulnerable
cableswig Not in release
coin3 Vulnerable
apache2 Not affected
apr-util Not affected
audacity Not affected
ayttm Not in release
celementtree Not in release
cmake Not affected
expat Fixed
gdcm Not affected
ghostscript Not affected
grmonitor Not in release
kompozer Not in release
libparagui1.1 Not in release
libxmltok Not affected
matanza Ignored
paraview Not affected
poco Not affected
python-xml Not in release
python2.4 Not in release
python2.5 Not in release
python2.6 Not in release
simgear Not affected
smart Not in release
tdom Not affected
texlive-bin Not affected
tla Not affected
vnc4 Not in release
vtk Not in release
w3c-libwww Not in release
wbxml2 Not affected
wxwidgets2.6 Not in release
wxwidgets2.8 Not in release
wxwindows2.4 Not in release
xmlrpc-c Fixed
xotcl Not affected
xulrunner Not in release
Show all 41 packages Show less packages

CVE-2008-4770

Medium priority

The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute...

1 affected package

vnc4

Package 20.04 LTS
vnc4 —
Show less packages

CVE-2006-2369

Medium priority

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1...

1 affected package

vnc4

Package 20.04 LTS
vnc4 —
Show less packages