Search CVE reports
1 – 10 of 49 results
Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh...
1 affected package
vtk9
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| vtk9 | Needs evaluation | Needs evaluation | — | — | 
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the...
1 affected package
vtk
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| vtk | Not in release | Not in release | — | — | 
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly...
1 affected package
vtk
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| vtk | Not in release | Not in release | — | — | 
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.
1 affected package
vtk
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| vtk | Not in release | Not in release | — | — | 
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
23 affected packages
expat, apache2, apr-util, tdom, cmake...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| expat | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | — | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | — | — | 
| cableswig | Not in release | Not in release | — | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Needs evaluation | 
| vtk | Not in release | Not in release | — | — | 
| smart | Not in release | Not in release | — | Needs evaluation | 
| firefox | Not affected | Not affected | — | — | 
| thunderbird | Not affected | Not affected | — | — | 
| libxmltok | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
Some fixes available 5 of 83
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...
23 affected packages
cadaver, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Needs evaluation | Needs evaluation | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| expat | Fixed | Fixed | Ignored | Ignored | 
Some fixes available 7 of 74
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
23 affected packages
smart, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| expat | Fixed | Fixed | Fixed | Fixed | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Not affected | Not affected | Not affected | Not affected | 
Some fixes available 6 of 73
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
tdom, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Not affected | Not affected | Not affected | Not affected | 
| expat | Fixed | Fixed | Fixed | Fixed | 
Some fixes available 13 of 80
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
23 affected packages
apache2, apr-util, cmake, ghostscript, texlive-bin...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Fixed | Fixed | Fixed | Fixed | 
| expat | Fixed | Fixed | Fixed | Fixed | 
Some fixes available 13 of 80
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| expat | Fixed | Fixed | Fixed | Fixed | 
| apache2 | Not affected | Not affected | Not affected | Not affected | 
| apr-util | Not affected | Not affected | Not affected | Not affected | 
| cmake | Not affected | Not affected | Not affected | Not affected | 
| ghostscript | Not affected | Not affected | Not affected | Not affected | 
| texlive-bin | Not affected | Not affected | Not affected | Not affected | 
| xmlrpc-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vnc4 | Not in release | Not in release | Not in release | Needs evaluation | 
| wbxml2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| swish-e | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| insighttoolkit4 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | 
| cadaver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| gdcm | Not affected | Not affected | Not affected | Needs evaluation | 
| ayttm | Not in release | Not in release | Not in release | — | 
| cableswig | Not in release | Not in release | Not in release | — | 
| coin3 | Not affected | Not affected | Not affected | Needs evaluation | 
| matanza | Ignored | Ignored | Ignored | Ignored | 
| tdom | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | 
| vtk | Not in release | Not in release | Not in release | — | 
| smart | Not in release | Not in release | Not in release | Needs evaluation | 
| firefox | Not affected | Not affected | Not in release | — | 
| thunderbird | Not affected | Not affected | Not in release | — | 
| libxmltok | Fixed | Fixed | Fixed | Fixed |